{"id":41334,"date":"2021-08-24T08:54:31","date_gmt":"2021-08-24T12:54:31","guid":{"rendered":"https:\/\/www.kaspersky.com\/blog\/?p=41334"},"modified":"2021-09-17T07:24:29","modified_gmt":"2021-09-17T11:24:29","slug":"fmwhatsapp-mod-downloads-malware","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com\/blog\/fmwhatsapp-mod-downloads-malware\/41334\/","title":{"rendered":"FMWhatsApp mod for WhatsApp downloads Trojans"},"content":{"rendered":"<p>We recently <a href=\"https:\/\/securelist.com\/triada-trojan-in-whatsapp-mod\/103679\/\" target=\"_blank\" rel=\"nofollow noopener\">discovered<\/a> that a version of popular WhatsApp mod FMWhatsApp includes an embedded Trojan. The Trojan, called Triada, downloads other malware to users\u2019 devices. Here\u2019s how it happened and why using modified versions of WhatsApp is dangerous.<\/p>\n<h2>Why use WhatsApp mods?<\/h2>\n<p>Not all users are happy with the official WhatsApp app. Some may feel a need for self-destructing messages or, conversely, the ability to view messages another user deleted. Others are after dynamic themes, and still others want to hide certain chats from the general list or automatically translate messages.<\/p>\n<p>Naturally, they want these features right away, not when WhatsApp\u2019s developers finally get around to implementing them. As a result, some users turn to the modified WhatsApp clients available online, which are fairly numerous and not hard to find.<\/p>\n<p>Fans of mods are not deterred even by WhatsApp\u2019s <a href=\"https:\/\/techcrunch.com\/2015\/01\/21\/whatsapp-cracks-down-on-third-party-apps-temporarily-bans-their-users-from-its-service\/\" target=\"_blank\" rel=\"nofollow noopener\">occasional<\/a> <a href=\"https:\/\/www.notebookcheck.net\/WhatsApp-is-now-banning-users-of-third-party-apps-GBWhatsApp-WhatsApp-Plus.414489.0.html\" target=\"_blank\" rel=\"nofollow noopener\">crackdown<\/a> on such modifications or the threat of account bans.<\/p>\n<p>The creators of WhatsApp mods often embed ads in them \u2014 understandably \u2014 along with the features users are looking for. Problems arise, however, from their use of third-party ad modules through which malicious code can sneak in under developers\u2019 radar.<\/p>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"kisa-generic-2\">\n<h2>Triada et al. in the FMWhatsApp mod<\/h2>\n<p>That\u2019s precisely what happened with FMWhatsApp, a popular WhatsApp mod. In version 16.80.0 the developers use third-party ad module that includes a Trojan. Our <a href=\"https:\/\/www.kaspersky.com\/mobile-security?icid=gl_kdailyplacehold_acq_ona_smm__onl_b2c_kdaily_wpplaceholder_sm-team___kisa____da04049114cf37d2\" target=\"_blank\" rel=\"noopener nofollow\">mobile antivirus<\/a> solution detects this malware as Trojan.AndroidOS.Triada.ef.<\/p>\n<p>We saw a similar situation in the spring of 2021 with the APKPure unofficial app store, whose developers also used an ad module from an unverified source, thereby <a href=\"https:\/\/www.kaspersky.com\/blog\/infected-apkpure\/39273\/\" target=\"_blank\" rel=\"noopener nofollow\">infecting their creation<\/a>, and consequently users, with the Triada Trojan (albeit a slightly different version).<\/p>\n<p>As in the case of the infected APKPure, the Triada Trojan in the dangerous version of the FMWhatsApp mod performs an intermediary function. First, it collects data about the user\u2019s device, and then, depending on the information, it downloads another Trojan.<\/p>\n<p>Triada\u2019s \u201cextras\u201d come in a variety of flavors \u2014 the infected version of FMWhatsApp downloads several types of malware to devices:<\/p>\n<ul>\n<li>Trojan-Downloader.AndroidOS.Agent.ic, a Trojan that downloads and runs other malicious modules;<\/li>\n<li>Trojan-Downloader.AndroidOS.Gapac.e, which downloads and runs other malicious modules and can also display full-screen ads at unexpected moments;<\/li>\n<li>Trojan-Downloader.AndroidOS.Helper.a, which downloads and runs the installer module of the <a href=\"https:\/\/securelist.com\/unkillable-xhelper-and-a-trojan-matryoshka\/96487\/\" target=\"_blank\" rel=\"nofollow noopener\">xHelper<\/a> Trojan and runs invisible ads in the background;<\/li>\n<li>Trojan.AndroidOS.MobOk.i, a Trojan that signs up for paid subscriptions;<\/li>\n<li>Trojan.AndroidOS.Subscriber.l, another Trojan that signs up for paid subscriptions;<\/li>\n<li>Trojan.AndroidOS.Whatreg.b, the most complex Trojan in the list, signs in to the WhatsApp account on the victim\u2019s phone, intercepting the login confirmation text. The device can then become a site for various types of illegal activity such as spam distribution or illegal trading.<\/li>\n<\/ul>\n<p>Our <a href=\"https:\/\/securelist.com\/triada-trojan-in-whatsapp-mod\/103679\/\" target=\"_blank\" rel=\"nofollow noopener\">Securelist post<\/a> delves more into the FMWhatsapp mod\u2019s Triada Trojan.<\/p>\n<h2>How to defend against such attacks<\/h2>\n<p>Practicing caution and using your device safely is key to keeping malware and other mobile nasties off your phone. Generally speaking, follow these tips to avoid trouble:<\/p>\n<ul>\n<li>Avoid installing apps from unofficial sources and use your device\u2019s settings to deny permission to install them. (If you need to install an app not from an official store, temporarily enable that permission and then disable it again);<\/li>\n<li>Use only official messaging apps, and download them only from official app stores \u2014 they may lack some features, but will not flood your phone with viruses;<\/li>\n<li>Check what permissions you\u2019ve granted to installed apps \u2014 <a href=\"https:\/\/www.kaspersky.com\/blog\/android-8-permissions-guide\/23981\/\" target=\"_blank\" rel=\"noopener nofollow\">some might pose a real threat<\/a>;<\/li>\n<li>Install a <a href=\"https:\/\/www.kaspersky.com\/mobile-security?icid=gl_kdailyplacehold_acq_ona_smm__onl_b2c_kdaily_wpplaceholder_sm-team___kisa____da04049114cf37d2\" target=\"_blank\" rel=\"noopener nofollow\">reliable mobile antivirus app<\/a> on your phone, and heed its warnings.<\/li>\n<\/ul>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"kisa-generic\">\n","protected":false},"excerpt":{"rendered":"<p>One version of popular WhatsApp mod FMWhatsApp uses an infected advertising module that downloads Trojans to smartphones.<\/p>\n","protected":false},"author":2624,"featured_media":41335,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[2683],"tags":[105,607,1475,723,546],"class_list":{"0":"post-41334","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-threats","8":"tag-android","9":"tag-messengers","10":"tag-triada","11":"tag-trojans","12":"tag-whatsapp"},"hreflang":[{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/fmwhatsapp-mod-downloads-malware\/41334\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/fmwhatsapp-mod-downloads-malware\/23215\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/fmwhatsapp-mod-downloads-malware\/18702\/"},{"hreflang":"ar","url":"https:\/\/me.kaspersky.com\/blog\/fmwhatsapp-mod-downloads-malware\/9354\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/fmwhatsapp-mod-downloads-malware\/25250\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/fmwhatsapp-mod-downloads-malware\/23319\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/fmwhatsapp-mod-downloads-malware\/22677\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/fmwhatsapp-mod-downloads-malware\/25859\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/fmwhatsapp-mod-downloads-malware\/25378\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/fmwhatsapp-mod-downloads-malware\/31296\/"},{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/fmwhatsapp-mod-downloads-malware\/9954\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/fmwhatsapp-mod-downloads-malware\/17995\/"},{"hreflang":"pl","url":"https:\/\/plblog.kaspersky.com\/fmwhatsapp-mod-downloads-malware\/15171\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/fmwhatsapp-mod-downloads-malware\/27232\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/fmwhatsapp-mod-downloads-malware\/31471\/"},{"hreflang":"nl","url":"https:\/\/www.kaspersky.nl\/blog\/fmwhatsapp-mod-downloads-malware\/27439\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/fmwhatsapp-mod-downloads-malware\/24262\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/fmwhatsapp-mod-downloads-malware\/29589\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/fmwhatsapp-mod-downloads-malware\/29394\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com\/blog\/tag\/android\/","name":"Android"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/41334","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/users\/2624"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/comments?post=41334"}],"version-history":[{"count":2,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/41334\/revisions"}],"predecessor-version":[{"id":41363,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/41334\/revisions\/41363"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/media\/41335"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/media?parent=41334"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/categories?post=41334"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/tags?post=41334"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}