Categories: Digital LifeNewsTech

New malware spreads itself by auto replying to all of your WhatsApp messages

Have you received a WhatsApp message with a suspicious link embedded? Whatever you do, don’t click on that link. The reason: a new wormable malware has been spreading on Android devices via WhatsApp, as reported by The Hacker News. 

According to security ESET malware researcher Lukas Stefanko:

This malware spreads via victim’s WhatsApp by automatically replying to any received WhatsApp message notification with a link to [a] malicious Huawei Mobile app,

So, how does this malware spread and infect other users? According to Stefanko, the malware uses WhatsApp’s quick reply feature to send messages with the malicious links as replies.

These links redirect potential victims to a convincing web page that resembles Google’s Play Store. It then prompts users to download and install a fake Huawei app. This malicious app then prompts users to grant it permission to read notifications as well as run in the background.

In addition, it also asks users to allow it to draw over other apps. If you are not familiar, this basically allows the malware-ridden app to overlay itself on top of other apps running on the device. This then allows it to capture and steal all your credentials like usernames and passwords.

Stefanko notes the malware only sends one message per hour to the same contact. This is done, so the app does not arouse suspicions at first and scarily enough, it remains operational as long as possible before it being detected and removed.

He added that the contents of the message and the link to the malicious app are fetched from a remote server. This means the malware can be used to redirect unsuspecting victims to other malicious websites and apps.

In its current form, the malware is only capable of sending automatic replies to other WhatsApp contacts. However, this could potentially be extended to other messaging apps that support Android’s quick reply function.

The malware researcher said this is the first time he has encountered an Android malware that can spread itself via WhatsApp messages. He added that the malware could potentially be spread through other forms of messaging like SMS, email, social media, groups chats and more.

This underscores the need for users to stick to only trusted sources when downloading third-party apps. Always verify that the app you are downloading is actually made by a genuine developer. Also, scrutinise every permission the app requests before granting it.

If you are interested to learn how the malware works, have a look at Stefanko’s Youtube video below:

[SOURCE]

Related reading

Recent Posts

Redmi A7 Pro now in Malaysia: Budget smartphone with 6,000mAh battery, 6.9″ 120Hz screen, priced from RM399

Xiaomi has launched its latest budget smartphone — the Redmi A7 Pro — here in…

3 hours ago

Malaysia’s under-16 social media ban plan faces growing pushback over privacy and human rights concerns

A group of civil society organisations (CSOs) and individuals has issued a joint letter urging…

12 hours ago

Malaysia’s EV policy and the BYD debate: Are affordable EVs at risk? | Let’s Talk About #140

Malaysia’s EV policy is back in focus, following growing debate over the conditions surrounding BYD’s…

1 day ago

Ryt Bank hits 1.2 million users, PayLater on Card and in-app investing are coming soon

Ryt Bank says it has surpassed 1.2 million users in just over seven months since…

2 days ago

EVPower deploys 80kW DC Charger at JJ Food Court in Johor Jaya, 50% off EV Charging until 30th April

EVPower has deployed a new DC Charger located at JJ Food Court in Taman Johor…

2 days ago

At RM35,888, OSIM’s New Chair Asks a Bold Question: Do You Want 5 Seats and a Boot, or 1 Seat and a French Audio System?

At RM35,888, the newly unveiled OSIM uDream·AI massage chair is priced just RM2,700 shy of…

3 days ago

This website uses cookies.