Newly-discovered WhatsApp spyware multiplying within the Telegram messenger is covertly hijacking personal information from its victims, a Kaspersky report said.
While the app modification is enhancing user experience through extra features, such as scheduled messages and customizable options, it is simultaneously harvested a trove of user information based on hundreds of thousands of downloads, perhaps as many as 340,000 in October alone, Kaspersky said.
The malware predominantly targets users who communicate in Arabic and Azeri, though victims have been identified globally, according to the security provider. Azerbaijan, Saudi Arabia, Yemen, Turkey, and Egypt witnessed the highest attack rates. While the preference leans towards Arabic and Azerbaijani-speaking users, the malware has also impacted individuals from the U.S., U.K., Germany, Russia and elsewhere.
"People naturally trust apps from highly followed sources, but fraudsters exploit this trust," said Dmitry Kalinin, security expert at Kaspersky. "The spread of malicious mods through popular third-party platforms highlights the importance of using official instant messaging (IM) clients. For robust personal data protection, always download apps from official app stores or official websites."
Attack Tactics Examined
Here’s how the modified client works:
Protecting Your Organization
To stay safe from infection, Kaspersky recommends: