UPDATED 20:41 EDT / NOVEMBER 05 2017

APPS

1M+ people get tricked into downloading fake WhatsApp messaging app

More than a million people are believed to have downloaded a malicious, fake version of Facebook Inc.’s WhatsApp messaging app from the Google Play store.

First spotted by users on Reddit Friday, the app, dubbed “Update WhatsApp Messenger” was listed as coming from “WhatsApp Inc.,” the official name of the Facebook-owned company. How the fake app was listed with the same name as the official company was explained by Hacker News, which found that those behind that app inserted a Unicode character space after the actual WhatsApp Inc. name that would not be visible to Google Play users.

The malicious app did provide some basic messaging functionality but primarily acted as a way to trick users into clicking third-party ads and downloading malicious software. As one Reddit user explained: “I’ve also installed the app and decompiled it … the app itself has minimal permissions (internet access) but it’s basically an ad-loaded wrapper which has some code to download a second apk, also called ‘whatsapp.apk.’ The app also tries to hide by not having a title and having a blank icon.”

fakewhatsapp2The app has since been removed from Google Play, but the fact it was listed long enough to have more than a million people download it once again raises questions about Google’s efforts to stop fake and malicious apps from getting listed. Seemingly once a month, an outbreak of fake apps is discovered on Google Play, including recent examples such as the discovery of fake cryptocurrency trading apps in October and an outbreak described as massive in September.

The risk of users downloading fake WhatsApp apps also remains. As of Sunday evening, a search in Google Play for WhatsApp (pictured) returns the official app in first position, but a fake app, going by the name of “Freе WhatsApp Messenger Update – Tips” from a developer listed as “WhatsApp Inc./” (including that forward slash at the end), sits in third position. A scroll further down the page also found numerous other examples of what appear to be fake WhatsApp apps.

Image: Pixabay

A message from John Furrier, co-founder of SiliconANGLE:

Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

  • 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
  • 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.
About SiliconANGLE Media
SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.