Tag Archive for: WhatsApp’s

WhatsApp’s cloned app spying on Indians via recording video, audio


New Delhi: India is among the countries with highest number of Android trojan detections and a cloned, third-party unofficial version of WhatsApp is leading in spying on people’s chats in the country, a new report has warned.

Behind a large portion of Android spyware detection in the past four months was ‘GB WhatsApp’ — a popular but cloned third-party version of WhatsApp, according to the report by cyber-security firm ESET.

Such malicious apps have a wide range of spying capabilities, including recording audio and video.

MS Education Academy

“The cloned app is not available on Google Play and, therefore, there are no security checks in place compared with the legitimate WhatsApp, and versions available on various download websites are riddled with malware,” said the report.

India (35 per cent) was also ranked second after China (53 per cent) as the geolocation for bots making up the largest internet of things (IoT) botnet called ‘Mozi’ from May to August 2022.

The IoT botnet ‘Mozi’ saw the number of bots drop by 23 per cdnt from 500,000 compromised devices to 383,000 in May-August.

However, China and India continued to have the highest number of IoT bots geolocated inside the respective countries.

“These statistics confirm the assumption that the ‘Mozi’ botnet is on autopilot, running without human supervision since its reputed author was arrested in 2021,” said the report.

Even with declining numbers, Russian IP addresses continued to be responsible for the largest portion of remote desktop protocol (RDP) attacks.

“Russia was also the country that was most targeted by ransomware, with some of the attacks being politically or ideologically motivated by the war,” said Roman Kovac, Chief Research Officer at ESET.

The report also examined threats mostly impacting home users.

“In terms of threats directly affecting virtual and physical currencies, a web skimmer known as Magecart remains the leading threat going after online shoppers’ credit card details,” said Kovac.

Source…

Sorry iPhone Users — WhatsApp’s Stunning New Update Is Not For You


So, this is nasty new surprise for millions of iPhone users. It seems that WhatsApp has fixed the most alarming security issue plaguing its 2 billion users. But not for you—this absolutely critical new fix is Android only. Your serious problem is not going away.

The issue is the account hijacks that continue to plague users worldwide. The fact this has not yet been addressed is stunning, given the scale of the issue and the publicity it has generated. But finally, it seems there is some relief. At least for Android users.

Some of these account hijacks are stupidly simple—tricking users into WhatsApp’s forwarding six-digit SMS verification codes that are then used by attackers to transfer your WhatsApp to their own phones. They then message your contacts, pretending to be you, usually requesting money. Other attacks are more complex, such as the “account suspension hack” we warned you about in April, where anyone can block your WhatsApp account by repeatedly entering incorrect codes against your number.

The first of these issues can be prevented by setting up 2FA inside WhatsApp—Settings / Account / Two-Step Verification. This is different to the code WhatsApp sends by SMS, and it prevents any trickster from stealing your account. The second can’t be prevented unless/until WhatsApp stops automating account suspensions without checking that the request comes from an account holder.

What’s always been most annoying about this problem is that it seems so ridiculous. There is a phone number associated with your WhatsApp account, a text is sent to that number to verify a new install, but the app cannot check that the phone on which it is being installed is the one associated with that same number. Cue the hijacks.

There are clearly privacy issues with WhatsApp pulling identifying data from the device—except that it does plenty of that anyway. This isn’t Signal we’re talking about. But even the suspension attack is so basic as to be laughable. It would not be difficult to find ways to prevent what is essentially a brute force attack on your account from a third-party device in a different location.

Anyway,…

Source…

Why WhatsApp’s ‘Backdoor’ Isn’t a Backdoor

A chorus of security experts say allegations WhatsApp’s end-to-end messaging platform has a backdoor are wrong and explain why reports making the claim are false.
Threatpost | The first stop for security news

WhatsApp’s Android App Has a Security Flaw – Wall St. Cheat Sheet

WhatsApp's Android App Has a Security Flaw
Wall St. Cheat Sheet
British newspaper The Guardian's story about the Android security hole notes that this is the second time in the last six months a security flaw has been discovered: “In October, a security researcher showed that it was possible to decrypt messages as

“android security” – read more