Security Affairs
Russian APT BlueDelta Uses HOOKEDGE to Target Defense and Diplomatic Organizations|PaperCut Zero-Day Under Active Attack: Emergency Patch Released|U.S. CISA adds Red Hat, Linux Kernel, Ajax.NET Professional, Microsoft SQL Server, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog|Cyberattack on UK Airport Operator MAG Exposes Data of 8.7 Million Customers Across Three Airports|Dark Caracal Deploys New Go Malware With Ethereum-Based C2 Fallback|Australian Police Charge Two Over TeamPCP Credential Theft|Meta to Pay Up to $18B Over Teen Social Media Use|CISA Warns Water Utilities: Find Your Exposed PLCs Before Attackers Do|OpenAI banned Russian ChatGPT accounts backing covert influence operation|CISA Red Team Fully Compromised Two Critical Infrastructure Orgs|FBI Seizes China-Linked Hacking Platforms QScan and QTRouter Used Against Critical Infrastructure|U.S. CISA adds Gitea flaw to its Known Exploited Vulnerabilities catalog|Russian APT BlueDelta Uses HOOKEDGE to Target Defense and Diplomatic Organizations|PaperCut Zero-Day Under Active Attack: Emergency Patch Released|U.S. CISA adds Red Hat, Linux Kernel, Ajax.NET Professional, Microsoft SQL Server, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog|Cyberattack on UK Airport Operator MAG Exposes Data of 8.7 Million Customers Across Three Airports|Dark Caracal Deploys New Go Malware With Ethereum-Based C2 Fallback|Australian Police Charge Two Over TeamPCP Credential Theft|Meta to Pay Up to $18B Over Teen Social Media Use|CISA Warns Water Utilities: Find Your Exposed PLCs Before Attackers Do|OpenAI banned Russian ChatGPT accounts backing covert influence operation|CISA Red Team Fully Compromised Two Critical Infrastructure Orgs|FBI Seizes China-Linked Hacking Platforms QScan and QTRouter Used Against Critical Infrastructure|U.S. CISA adds Gitea flaw to its Known Exploited Vulnerabilities catalog|
Advertisement

Ad Placeholder

Full Width × 90

Breaking News

WhatsApp Pink malware spreads via group chat messages

A WhatsApp malware dubbed WhatsApp Pink is able to automatically reply to victims’ Signal, Telegram, Viber, and Skype messages. A WhatsApp malware dubbed WhatsApp Pink has now been updated, authors have implemented the ability to automatically respond to victims’ Signal, Telegram, Viber, and Skype messages. WhatsApp Pink is a fake app that was first discovered this week, […]

Wi-Fi

A WhatsApp malware dubbed WhatsApp Pink is able to automatically reply to victims’ Signal, Telegram, Viber, and Skype messages.

A WhatsApp malware dubbed WhatsApp Pink has now been updated, authors have implemented the ability to automatically respond to victims’ Signal, Telegram, Viber, and Skype messages.

WhatsApp Pink is a fake app that was first discovered this week, it poses as a “pink” themed version of the legitimate app. The tainted app includes malicious code that allows attackers to fully compromise a device, most of the infections were reported by WhatsApp users in the Indian subcontinent

The security expert Rajshekhar Rajaharia recently discovered that WhatsApp Pink is able to spread via group chat messages that contain APK download links.

The link shared via group messages points to a page where visitors can download the WhatsApp Pink APK (WhatsappPink.apk).

Early this year, the ESET malware researcher Lukas Stefanko discovered an Android malware implementing wormable capabilities, like WhatApp Pink, it was spreading through WhatsApp chat messages.

Below the video shared by Stefanenko showing WhatsApp Pink:

https://www.instagram.com/reel/CN10sNGg2b8/?igshid=ayxxmsjaobv0

“This updated version of the Trojan does not send automatic responses only to messages that arrive from WhatsApp, but also to messages received in other instant messaging applications, which could be the reason for its apparent wider spread,” said Stefanko.

“The Trojan sends these automatic responses to any message that the user receives in applications such as WhatsApp, WhatsApp Business, Signal, Skype, Viber, Telegram.”

Once the app is installed on the device, when the user will click on its icon, the app disappears claiming that it was never even installed.

“The victim will then receive a message, to which they will have to reply in order to unwittingly cause it to propagate further.” reads the post published by ESET.

Experts from ESET speculate the app is under development, it could be a “test version,” and more malicious variants could be developed in the future.

The good news is that Android users that have installed the WhatsApp Pink app can simply remove it from the Settings and the App Manager submenu.

If you want to receive the weekly Security Affairs Newsletter for free subscribe here.

Follow me on Twitter: @securityaffairs and Facebook

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, WhatsApp)

[adrotate banner=”5″]

[adrotate banner=”13″]