惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

F
Full Disclosure
博客园 - 聂微东
博客园_首页
人人都是产品经理
人人都是产品经理
N
News | PayPal Newsroom
云风的 BLOG
云风的 BLOG
U
Unit 42
T
Tailwind CSS Blog
Recent Announcements
Recent Announcements
Security Archives - TechRepublic
Security Archives - TechRepublic
T
The Blog of Author Tim Ferriss
Stack Overflow Blog
Stack Overflow Blog
The Register - Security
The Register - Security
The Hacker News
The Hacker News
博客园 - Franky
Engineering at Meta
Engineering at Meta
Jina AI
Jina AI
月光博客
月光博客
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
F
Fortinet All Blogs
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
C
Check Point Blog
C
Cyber Attacks, Cyber Crime and Cyber Security
有赞技术团队
有赞技术团队
TaoSecurity Blog
TaoSecurity Blog
博客园 - 司徒正美
GbyAI
GbyAI
G
Google Developers Blog
B
Blog
G
GRAHAM CLULEY
Y
Y Combinator Blog
雷峰网
雷峰网
爱范儿
爱范儿
酷 壳 – CoolShell
酷 壳 – CoolShell
D
Darknet – Hacking Tools, Hacker News & Cyber Security
Microsoft Azure Blog
Microsoft Azure Blog
WordPress大学
WordPress大学
V
V2EX
罗磊的独立博客
Know Your Adversary
Know Your Adversary
AWS News Blog
AWS News Blog
T
Troy Hunt's Blog
S
SegmentFault 最新的问题
P
Privacy & Cybersecurity Law Blog
T
Threat Research - Cisco Blogs
H
Help Net Security
N
Netflix TechBlog - Medium
Help Net Security
Help Net Security
L
LangChain Blog
D
Docker

Consumer Insights

The ransomware negotiator who was working for the other side After years on the run, alleged Ryuk ransomware operator pleads guilty INTERPOL crackdown shows scammers shifting to social media Meta lets strangers remix your public Instagram photos with AI—here’s how to opt out Invited to a "job interview" with Netflix or OpenAI? Beware! Your Google password could be at risk Two arrested over credit card phishing - as the Netherlands is named Europe's worst for payment fraud India pauses WhatsApp username feature over security concerns Alleged teen ransomware hustler faces US charges after arrest in Finland WhatsApp usernames explained: how to reserve yours and stay safe Scammers race to cash in on Venezuelan earthquake disaster USB drives carrying China-linked malware infected Japanese military networks for nearly a year WhatsApp tests new safety prompt before you chat with strangers Social media is worth celebrating. It's also worth protecting. Polish police dismantle SIM-swap gang accused of crypto theft Operation Endgame deals fresh blow to StealC and Amadey malware networks Hacker hijacks Brazil's national alert system, sending "misanthropy" to millions of phones Cybercrime now rivals traditional crime across parts of Asia Apple's Hide My Email tweak leaves privacy fans fuming Americans lost $3.5 billion to imposter scams last year — and the scams are getting harder to spot Scammers have killed the physical Steam Gift cards Crypto investment scam sends couriers to collect victims' cash, FBI warns Maine forced to take down data breach portal after fake notices filed with authorities Privacy own-goal: World Cup blunder leaks Lionel Messi's passport details Why schools remain one of cybercriminals' favourite targets WhatsApp detects new spyware activity from Israel’s NSO Group despite court order Got a LinkedIn message from a recruiter? It might be Chinese intelligence, warn FBI and MI5 Europol cracks down on illegal streaming globally Hackers didn't hack Instagram; they just asked Meta AI FBI Warns Fans About FIFA Scams Ahead of 2026 World Cup Virtual knife, real lawsuit: Counter-Strike skin dispute ends in court As Deepfakes Spread, YouTube Makes AI Labels Harder to Miss Carnival breach exposes data of nearly 6 million people Police arrest man following hack of Ajax football club MyPillow listed on ransomware gang's leak site, but denies it has been breached FBI warns criminals impersonating IT support to breach law firms FBI warns of Kali365 phishing kit that breaks into Microsoft 365 accounts — no password required Telecom Executives Plead Guilty to Tech Support Fraud 7-Eleven data breach exposes data of 185,000 people ASIC Warns Australians About Crypto Trading Scams Google Search AI Mode brings a major overhaul Deleted Google API keys may remain active for 23 minutes Ukrainian police identify perp in $721k infostealer scheme Steam removes horror game after malware steals player data FBI: Crypto ATM Scams Keep Growing as Americans Lose Millions FBI warns students and staff that ShinyHunters may come knocking after Canvas breach Scam Centers Under Pressure as INTERPOL Makes More Arrests FBI Warns Older Adults Lost Billions to Scammers Burst Statistics WordPress flaw under attack Android 17 Will Let Users Verify Whether Their OS Is Legit Suspected Dream Market kingpin arrested after gold bars sent to his home address BitLocker zero-day exposes Windows drives as PoC goes public Apple Fixes ‘Persistent Notifications’ Flaw on Older iPhones Football Ticket Scams Are Rising Fast, Lloyds Bank Warns When ransomware gets physical: cybercriminals turn to threats of violence iPhone-to-Android Texts Are Now Encrypted (RCS Messaging) UK Water Supplier Fined Nearly £1 Million After Hackers Roamed Networks for Almost 2 Years Instagram Drops Encrypted DMs — What This Means for You New fear: Man films woman with smart glasses, seeks money to take video down ClickFix Campaign Uses Compromised WordPress Sites to Spread Vidar Stealer in Australia Inside Department 4: Russia's secret school for hackers Ubuntu’s new AI dreams attracted a very old-fashioned crypto scam on X Chrome 4GB AI model: What weights.bin does Sri Lanka makes 37 arrests as it raids another scam centre DAEMON Tools Lite breach prompts urgent update after malware-laced installer Brits Lost £102 Million to Romance Scams Last Year The Online Safety Act Is Changing the Internet for Kids World Password Day 2026 How Hackers Stole and Sold Roblox Accounts for $250,000 Before Getting Caught Four Years in Prison for Cybersecurity Pros Turned Ransomware Attackers Teenager alleged to be Scattered Spider hacker arrested in Finland, faces US extradition 276 Arrested in Crypto Scam Crackdown Popular WordPress redirect plugin found with years-old backdoor Iran-linked Handala hackers leak US Marines data, send chilling WhatsApp threats Alleged Silk Typhoon hacker extradited to the United States to face charges FTC: Social Media Scams Cost Americans $2.1 Billion in 2025 French police arrest 21-year-old "HexDex" hacker over 100 alleged data breaches iOS Flaw Exposed ‘Deleted’ Signal Messages Sony Starts Enforcing PlayStation Age Verification; UK and Ireland Are First Ransomware ‘Negotiator’ Faces 20 Years in Prison for Allegedly Betraying His Employers You’ve Got Mail and It’s Tracking Your Warship Crypto Investment Scam Costs Woman in Hong Kong Nearly $1 Million Operation PowerOFF warns 75,000 DDoS users Singer loses life savings to fake wallet downloaded from the Apple App Store AgingFly malware targets Ukraine government, hospitals 108 malicious Chrome extensions caught stealing Google and Telegram data from 20,000 users Rockstar Games confirms breach after ShinyHunters leaks stolen analytics data FBI: Cybercrime Losses Hit $21 Billion in 2025, Fueled by AI Life imprisonment for Cambodian scam compound operators - but will it make a difference? Fake Claude Code leak on GitHub spreads Vidar malware Apple Expands ‘DarkSword’ Patch to More iPhones and iPads Nigerian romance scammer jailed after being caught out by fellow fraudster Fake CERT-UA emails spread AGEWHEEZE in ukraine Alleged RedLine malware developer extradited to United States The Scam That Tricks You Into Infecting Your Own Mac Iranian hackers breach FBI director's personal email, and post his CV and photos online Don't Ignore This Security Alert Apple Sent to iPhone Lock Screens Meta and YouTube Designed Addictive Platforms, Jury Finds TikTok Business phishing campaign targets advertisers Lapsus$ claims AstraZeneca breach exposes code and credentials How one man used 10,000 bots to steal $8,000,000 from music artists
Fake WhatsApp Clone Used in Spyware Campaign, Meta Warns
2026-04-02 · via Consumer Insights

A counterfeit WhatsApp application was used in a targeted spyware campaign affecting around 200 users — primarily in Italy, Meta has warned.

Key takeaways:

  • Attackers distributed a counterfeit version of WhatsApp that functioned as surveillance software once installed.
  • Instead of hacking the app, attackers relied on deception, tricking victims into installing the malicious version themselves.
  • The campaign appears targeted, with links to an Italian surveillance vendor.
  • Victims were duped into sideloading the app, bypassing app store protections.
  • Once installed, such apps can collect messages, contacts, location data, and even activate microphones or cameras.
  • WhatsApp’s official app, infrastructure, and end-to-end encryption were not compromised.
  • Meta is taking action against the company linked to the spyware campaign.

WhatsApp users are once again in the crosshairs of spyware operators — but the latest attack didn’t rely on a hidden exploit or a missed call. Instead, it was disguised as something far more familiar: a fake version of WhatsApp itself.

The company logged users out of their WhatsApp accounts to prevent further data theft. It then sent warning notifications to the affected users, urging them to use only official applications.

A fake app with real surveillance capabilities

A fake app doesn’t need a zero-day vulnerability if it can convince you to install it.

According to Meta, the malicious software masqueraded as a legitimate WhatsApp client but functioned as spyware once installed. The company says around 200 individuals were targeted in the campaign, which has been linked to an Italian spyware vendor.

Unlike traditional app-based threats distributed through official stores, this fake version was sideloaded — meaning victims were tricked into installing it outside of their official app store.

Once installed, the malicious app granted attackers extensive access to a victim’s device. Spyware apps are typically designed to expose messages, photos, grant access to the mic and cameras, steal geolocation data, and more.

“To protect our users from this type of malicious activity, Meta constantly monitors its network for signs of compromised or unofficial clients,” the company said in a statement. “We are not experiencing a breach of WhatsApp's official apps, infrastructure, or encryption. Users' personal communications via our official app continue to be protected by end-to-end encryption and default privacy settings.”

Source: La Republica

Part of a broader spyware ecosystem

While details of the specific spyware capabilities are still emerging, the campaign fits a pattern.

Spyware operators have long targeted WhatsApp due to its massive user base and the sensitive nature of conversations on the platform.

Previous incidents have involved sophisticated tools like Pegasus, which exploited vulnerabilities to silently infect devices and monitor journalists, activists and other targets.

More recently, though, attackers have started turning to impersonation tactics — creating fake versions of trusted apps to trick people into installing malware.

Security researchers have recently observed similar campaigns where spyware hides inside counterfeit messaging or social media apps. From there, it can harvest messages and call logs, and even activate cameras.

Meta says it has taken steps to disrupt the campaign and is working with app store providers to prevent further abuse.

The company is also pursuing legal action against those behind the spyware operation, continuing a broader effort to crack down on commercial surveillance vendors.

According to reports, the fake WhatsApp clone was developed by ASIGINT, a subsidiary of SIO Spa, an Italian company active in the field of interceptions and surveillance.

This follows a series of legal battles in recent years, including a major case against NSO Group, where Meta accused the company of exploiting WhatsApp infrastructure to spy on users.

How spyware works

Spyware is one the most dangerous types of malware, not just because it can steal sensitive data, but also because attackers often infect target devices without input from the victim. Spyware is typically used to covertly by various people — from jealous spouses to state-sponsored actors — to observe and collect information about a target. Dissidents, journalists and political figures are common victims.

The typical traits of spyware:

·      Stealthy operation – runs silently in the background, often without user awareness

·      Data collection – steals messages, credentials, browsing activity, and other sensitive data

·      Surveillance capabilities – can monitor activity, track location, and profile behavior

·      Audio/video access – may activate microphones or cameras to record surroundings

·      Persistence mechanisms – modifies system settings or installs components to remain undetected

How to stay safe (advice for consumers)

This campaign reinforces a few essential security habits:

  • Download apps only from official stores (App Store, Google Play)
  • Avoid sideloading — i.e. installing apps via links, profiles, or unknown sources
  • Be wary of modified, premium, or free versions of popular apps
  • Keep your device updated to reduce exposure to known threats
  • Equip your device with a trusted, independent security solution capable of detecting and blocking malware

You may also want to read:

What Are the Risks of Sideloading Apps on Your Smartphone?

How Spyware Infects Smartphones and How to Defend Against It

‘Update iOS to Protect Your Data’ – Apple Urges Users to Patch Against Coruna and DarkSword Exploits

The Scam That Tricks You Into Infecting Your Own Mac