Researchers reported that a malicious modified version of WhatsApp was being distributed through seemingly legitimate Android applications, allowing attackers to compromise users who installed the software outside official channels. The campaign relied on repackaged apps that appeared benign but delivered a trojanized WhatsApp mod, expanding the reach of malware through trusted-looking distribution paths rather than direct phishing alone.
The activity highlights the risk posed by unofficial messaging clients and third-party app ecosystems, where attackers can hide malware inside popular software variants to steal data, abuse device access, or deploy additional payloads. The incident underscores that users and organizations should restrict installations to official app stores and vetted software sources, especially for high-use communications platforms such as WhatsApp.

Trace attribution and downstream blast radius.
1 event from the most recent confirmed update back to the earliest known activity.
Kaspersky's Securelist published research describing a malicious WhatsApp modification being distributed through legitimate applications, indicating a malware distribution campaign targeting users seeking unofficial WhatsApp mods.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.