WhatsApp Spyware Attack: Critical Flaw Lets Attackers Access User Data
Key Takeaways Approximately 200 WhatsApp users, primarily in Italy, were targeted with sophisticated government-grade spyware via a fraudulent messaging app clone. The malicious campaign was...
Key Takeaways
- Approximately 200 WhatsApp users, primarily in Italy, were targeted with sophisticated government-grade spyware via a fraudulent messaging app clone.
- The malicious campaign was orchestrated by ASIGINT, an Italian cyber intelligence firm, distributing the spyware known as “Spyrtacus.”
- The attack bypassed official app stores through social engineering, tricking users into installing the fake application, rather than exploiting a technical vulnerability in WhatsApp itself.
- The spyware granted extensive access to sensitive user data, including messages, call logs, and covert audio/video recording.
- Meta intervened by logging out affected users and alerting them to delete the malicious client, emphasizing that the official WhatsApp platform remained secure.
Meta has issued a warning to approximately 200 WhatsApp users, predominantly located in Italy, confirming that their devices were compromised by a weaponized, fraudulent version of the popular messaging application. This malicious software was not distributed through official app stores but instead relied on sophisticated social engineering tactics to trick targets into installing a spyware-laden clone.
Table Of Content
The deceptive application was meticulously crafted to mirror the legitimate WhatsApp client’s interface, aiming to fool unsuspecting victims. It was presented to targeted individuals as either a crucial update or an exclusive alternative variant of the widely used communication platform.
However, rather than functioning as a standard messaging tool, this clone secretly operated as a Trojan horse, harboring government-grade spyware within its code.
The malicious campaign has been attributed to ASIGINT, an Italy-based technology firm specializing in cyber intelligence solutions. ASIGINT operates as a subsidiary of SIO Spa, a company based in Cantù with a historical background in providing interception and surveillance technologies to governmental and institutional clients.
The firm publicly markets itself as a developer of high-performance, field-proven cybersecurity and digital surveillance solutions on its official website.
Attackers sidestepped the robust security protocols of both the Apple App Store and Google Play Store by leveraging less-controlled, third-party distribution channels. Their strategy heavily relied on social engineering—a psychological manipulation technique designed to persuade specific individuals to willingly download unverified software. This indicates the attack’s success stemmed from human vulnerability and misplaced trust, rather than any technical zero-day exploit.
Security researchers have identified the underlying malware embedded within these fake applications as “Spyrtacus,” a surveillance tool found within the spyware’s codebase. Once installed on a victim’s iPhone or Android device, Spyrtacus grants external actors extensive access to sensitive smartphone data.
This unauthorized access allows the software to illicitly steal text messages, extract chat histories, copy call logs, and even covertly record audio and video using the device’s microphone and camera.
Meta Warns of Sophisticated Attack
Meta’s internal security team proactively identified approximately 200 individuals who had successfully downloaded and activated this malicious third-party client. The tech giant noted that this surveillance campaign was highly targeted, not a mass-distribution effort, with the vast majority of victims residing in Italy.
While Meta has not publicly disclosed the specific identities of the targets, the nature of the spyware strongly suggests they were individuals of particular interest to the surveillance firm’s clients.
Upon discovering the active surveillance campaign, Meta immediately intervened to protect the targeted individuals from further data extraction. The company proactively logged affected users out of their WhatsApp accounts and severed the unauthorized connections to the platform’s servers.
Victims subsequently received a direct alert warning them about the severe privacy risks and instructing them to immediately delete the fraudulent client, Repubblica reported.
WhatsApp explicitly emphasized that this targeted espionage operation did not exploit any inherent vulnerabilities within the official application, its infrastructure, or its cryptographic protocols. Personal communications sent through the legitimate WhatsApp application remain fully protected by the platform’s standard end-to-end encryption and default privacy settings.
The company maintains continuous monitoring systems specifically designed to detect and block compromised or unofficial clients attempting to access its network.
This is not the first instance of SIO Spa being implicated in distributing deceptive surveillance applications. In early 2025, security researchers exposed a similar Android-based campaign by the company that utilized fake customer support applications impersonating Italian mobile providers such as TIM, Vodafone, and WINDTRE. This latest operation marks a significant escalation in their tactics, as they have now successfully expanded their spyware capabilities to target Apple’s highly restricted iOS ecosystem.
What You Should Do
- Immediately Delete Unofficial Apps: If you suspect you have downloaded an unofficial or fraudulent version of WhatsApp, delete it from your device immediately.
- Perform a Factory Reset: Cybersecurity experts strongly recommend performing a factory reset on your device to completely eradicate any lingering spyware components and ensure a clean slate.
- Reinstall from Trusted Sources: After a factory reset, reinstall the official WhatsApp application exclusively from trusted digital storefronts, such as the Apple App Store or Google Play Store, to ensure your communications remain secure.
- Be Wary of Social Engineering: Always be cautious of unsolicited messages or prompts asking you to download applications from unofficial sources, click suspicious links, or install “updates” that do not originate from your device’s official app store.
- Run Security Scans: Conduct a comprehensive security scan using reputable antivirus or anti-malware software on your device after removal to detect any residual threats.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.