WhatsApp said it notified about 200 users, mostly in Italy, after they were tricked into installing an unofficial iPhone version of WhatsApp embedded with spyware. The company said the incident did not stem from a vulnerability in WhatsApp itself, but from highly targeted social engineering that led victims to download the malicious client. WhatsApp logged affected users out, warned them of the privacy and security risks, and urged them to delete the fake app and reinstall the official version.
The company attributed the operation to ASIGINT, a subsidiary of Italian spyware maker SIO, and said it plans to send SIO a formal legal demand to halt the activity. The campaign adds to scrutiny of Italian surveillance vendors, following earlier reporting on SIO-linked Android spyware, including fake WhatsApp apps associated with Spyrtacus, and a separate WhatsApp notification campaign tied to Paragon Solutions and its Graphite spyware that reportedly targeted journalists and pro-immigration activists in Italy.

Get the infrastructure and lures behind it.
8 events from the most recent confirmed update back to the earliest known activity.
Alongside its disclosure, WhatsApp said it planned to send SIO a formal legal demand ordering the company to stop the malicious activity. The move signaled a potential escalation beyond user notifications into legal action.
WhatsApp said it notified about 200 affected users, logged them out of the malicious client, warned them of privacy and security risks, and urged them to remove the fake app and install the official version. Most of the impacted users were reported to be in Italy.
WhatsApp said the spyware operation behind the fake iPhone app was carried out by ASIGINT, a subsidiary of Italian spyware maker SIO. The company publicly connected the campaign to the Italian surveillance vendor ecosystem.
Around 200 users, primarily in Italy, were socially engineered into installing an unofficial iPhone version of WhatsApp that contained government spyware. WhatsApp said the malicious app was not the result of a vulnerability in its service.
Before this newly disclosed incident, WhatsApp had warned roughly 90 users, including journalists and pro-immigration activists, about targeting linked to Paragon Solutions' Graphite spyware in Italy. The case formed part of a broader spyware scandal involving Italian surveillance vendors.
Prior reporting identified Italian spyware maker SIO as distributing spyware through malicious Android applications, including fake WhatsApp versions. The spyware associated with these apps was identified as Spyrtacus.
In a December 2024 ruling referenced in the coverage, a court found NSO Group liable for targeting WhatsApp users with Pegasus spyware. The decision was part of WhatsApp's ongoing legal battle against NSO.
Kaspersky previously reported that operators distributed the Spyrtacus spyware through Google Play in 2018. By 2019, the campaign had shifted to fake websites impersonating Italian internet providers to deliver the malware.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
9 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcecybersecuritynews.com
Open sourcethehackernews.com
Open sourcesecurityaffairs.com
Open sourceteiss.co.uk
Open sourcetechcrunch.com
Open sourcerepubblica.it
Open sourcetherecord.media
Open sourcetechcrunch.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.