Cybersecurity researchers have discovered a new malicious “WhatsApp spy mod”, which has attacked messaging platform Telegram users more than 340,000 times in October alone, a new report said on Friday.
According to IANS, this malware mainly targets users who communicate in Arabic and Azeri, with victims identified globally.
As users turn to third-party mods for popular messaging apps to add extra features, the researchers explained that some of these mods, while enhancing functionality, also come with hidden malware.
According to them, the new WhatsApp mod offers not only additions like scheduled messages and customisable options, but it also contains a malicious spyware module.
The modified WhatsApp client’s manifest file includes suspicious components (a service and a broadcast receiver) not present in the original version.
The receiver initiates a service, launching the spy module when the phone is powered on or charging.
Once activated, the malicious implant sends a request with device information to the attacker’s server.
This data covers IMEI, phone number, country and network codes, and more.
It also transmits the victim’s contacts and account details every five minutes as well as able to set up microphone recordings and exfiltrate files from external storage, the report said.
The highest attack rates were recorded in Azerbaijan, Saudi Arabia, Yemen, Turkey, and Egypt. While the preference is for Arabic and Azerbaijani-speaking users, it also affects people from the US, Russia, the UK, Germany, and other countries.
To stay safe, experts recommend using official marketplaces, downloading apps and software from reputable and official sources, and avoiding third-party app stores, as the risk they may host malicious or compromised apps is higher.
“The spread of malicious mods through popular third-party platforms highlights the importance of using official IM clients. However, if you need some extra features not present in the original client, you should consider employing a reputable security solution before installing third-party software, as it will protect your data from being compromised,” said Dmitry Kalinin, a security expert at Kaspersky.
MIB extends by 4 weeks ban on news channels’ TRP by BARC India
Reliance eyes LEO satellite play to rival Starlink in India: ET report
FIFA offered $20mn for WC’26 broadcast rights for India market
IPL franchise Rajasthan Royals get new owners in Mittals, Poonawalla
Netflix leads India’s 2025 theatrical streaming race: Ormax study
TRAI extends submission date for satcom spectrum consultations
AAAI to mark 80 years, brings industry together on May 19
Ex-CEO Prasar Bharati Shashi Vempati named CBFC chief
Lakshvir Singh pushed limits training as hockey player for ‘Lukkhe’ 

