Android users fooled by fake WhatsApp

By

Malicious app sneaks into Google Play store.

A million Android users have been duped by a fake version of the popular WhatsApp messaging application after a malicious version snuck into Google's official Play app store.

Android users fooled by fake WhatsApp

Reddit reader dextergenius decompiled the fake app in Google Play and found that it tries to deliver advertisements to users who have downloaded and installed it.

It was also programmed to download a second Android package, also named whatsapp.apk. This could contain arbitrary code that users had not opted to run on their devices.

The developer of the malicious app used Unicode characters at the end of the fake app's name so it wouldn't clash with the real WhatsApp.

Once installed, the fake WhatsApp tried to hide itself by not having a title and using a blank icon.

When users spotted the fake WhatsApp the developers tried to change their name as well as that of the fake app.

The fake WhatApp has been removed from the Play store by Google, but not before it was downloaded and installed a million times.

In August Google removed more than 500 apps from Play that contained the malicious Igexin software development kit that could download arbitrary plug-ins.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

CBA using facial recognition logins to verify disputed payments

CBA using facial recognition logins to verify disputed payments

Top US diplomat impersonated with AI by unknown actor

Top US diplomat impersonated with AI by unknown actor

UK police arrest four over cyberattacks on M&S, Co-op and Harrods

UK police arrest four over cyberattacks on M&S, Co-op and Harrods

Google Gemini for Workspace vulnerable to prompt injection attacks

Google Gemini for Workspace vulnerable to prompt injection attacks

Log In

  |  Forgot your password?