Home News Computing (Image credit: Reliance Industries) Multiple WhatsApp knockoff applications have been discovered stealing the legitimate WhatsApp user access keys, researchers have found. With these keys, the apps’ authors can run all kinds of malicious campaigns, including one where the victims lose their hard-earned money.Cybersecurity researchers from Kaspersky recently discovered two messaging apps (opens in new tab) for Android, obviously targeting WhatsApp users. One is called YoWhatsApp, and the other WhatsApp Plus. Both these apps offer pretty much the same functionalities as the actual WhatsApp app, and then some. As per the report, YoWhatsApp apparently also comes with a customizable interface, and individual chat room blocks.Stealing access keysWhat users don’t see, however, is these apps stealing legitimate WhatsApp’s access keys and sending them to the knockoff’s authors, giving the attackers access to the victims’ user accounts. According to Kaspersky, the keys can be used in open-source utilities and allow attackers to perform various actions without the user’s consent. Besides actions, the attackers can also eavesdrop on the conversations, steal identity (opens in new tab) data, and similar.The researchers also said the attackers could use this access to subscribe the victims to premium services, charging them in the process and generating income.The…
Read More










