• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
canesspy spyware discovered in modified whatsapp versions

CanesSpy Spyware Discovered in Modified WhatsApp Versions

You are here: Home / General Cyber Security News / CanesSpy Spyware Discovered in Modified WhatsApp Versions
November 3, 2023

Cybersecurity researchers have unearthed a quantity of WhatsApp mods for Android that come equipped with a adware module dubbed CanesSpy.

These modified variations of the fast messaging application have been observed propagated by using sketchy sites marketing these kinds of application as well as Telegram channels utilized primarily by Arabic and Azerbaijani speakers, one of which boasts 2 million customers.

“The trojanized consumer manifest consists of suspicious elements (a provider and a broadcast receiver) that can not be discovered in the authentic WhatsApp consumer,” Kaspersky security researcher Dmitry Kalinin reported.

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


Cybersecurity

Especially, the new additions are intended to activate the adware module when the phone is switched on or commences charging.

It subsequently proceeds to create call with a command-and-regulate (C2) server, followed by sending data about the compromised product, this sort of as the IMEI, phone range, mobile nation code, and mobile network code.

CanesSpy also transmits details about the victim’s contacts and accounts every five minutes, in addition to awaiting additional recommendations from the C2 server each moment, a placing that can be reconfigured.

This features sending data files from external storage (e.g., detachable SD card), contacts, recording sound from the microphone, sending knowledge about the implant configuration, and altering the C2 servers.

Modified WhatsApp

The point that the messages sent to the C2 server are all in Arabic indicates that the developer at the rear of the procedure is an Arabic speaker.

Additional assessment of the operation shows that the spyware has been energetic since mid-August 2023, with the campaign largely targeting Azerbaijan, Saudi Arabia, Yemen, Turkey, and Egypt.

Cybersecurity

The development marks the ongoing abuse of modified versions of messaging products and services like Telegram and WhatsApp to distribute malware to unsuspecting end users.

“WhatsApp mods are mainly distributed by way of 3rd-party Android application stores, which normally lack screening and fail to acquire down malware,” Kalinin mentioned. “Some of these assets, this sort of as 3rd-party application merchants and Telegram channels, delight in sizeable popularity, but that is no warranty of basic safety.”

Observed this post intriguing? Adhere to us on Twitter  and LinkedIn to read a lot more exclusive content material we submit.


Some areas of this article are sourced from:
thehackernews.com

Previous Post: «48 malicious npm packages found deploying reverse shells on developer 48 Malicious npm Packages Found Deploying Reverse Shells on Developer Systems
Next Post: Predictive AI in Cybersecurity: Outcomes Demonstrate All AI is Not Created Equally predictive ai in cybersecurity: outcomes demonstrate all ai is not»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.