Researchers found the Android Trojan Triada embedded in the modified WhatsApp client FMWhatsApp 16.80.0 through a compromised advertising SDK. Detected as Trojan.AndroidOS.Triada.ef, the malware collects device identifiers and installed app package data, registers infected devices with a remote server, and then downloads, decrypts, and executes additional malicious components on the handset.
Observed follow-on payloads included downloaders, ad-fraud modules, premium-subscription fraud malware, and a component capable of registering a victim’s WhatsApp account on attacker-controlled infrastructure. Because users of the modded app commonly grant SMS-reading permissions, the malware can intercept verification codes, automate fraudulent premium-service signups, and support WhatsApp account takeover-related activity.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
Technical analysis showed that downloaded modules could sign victims up for paid subscriptions, display fraudulent ads, and abuse SMS-reading permissions to intercept confirmation codes. One payload, Trojan.AndroidOS.Whatreg.b, could request WhatsApp verification codes and support sign-in activity on attacker-controlled infrastructure.
Researchers observed the embedded Triada component collecting device and package information, registering infected devices with a remote server, and downloading, decrypting, and launching additional payloads. Identified payloads included Agent.ic, Gapac.e, Helper.a, MobOk.i, Subscriber.l, and Whatreg.b.
Kaspersky researchers found that the unofficial Android app FMWhatsapp version 16.80.0 contained the Triada Trojan embedded alongside an advertising SDK. The malicious component was detected as Trojan.AndroidOS.Triada.ef.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 11 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.