Advertisement
Top
image credit: Pxhere

Malicious WhatsApp mod distributed through legitimate apps

October 12, 2022

Last year, we wrote about the Triada Trojan inside FMWhatsApp, a modified WhatsApp build. At that time, we discovered that a dropper was found inside the distribution, along with an advertising SDK. This year, the situation has repeated, but with a different modified build, YoWhatsApp version 2.22.11.75. Inside it, we found a malicious module that we detect as Trojan.AndroidOS.Triada.eq.

The module decrypted and launched the Trojan.AndroidOS.Triada.ef main payload.

Read More on Securelist