WhatsApp identified a fake iOS client created by Italian spyware company SIO/ASIGINT. The fake app was distributed via social engineering, tricking about 200 users, mostly in Italy, into installing spyware. WhatsApp logged out these users and warned them about privacy risks. This attack did not exploit any WhatsApp vulnerability; official apps remain protected by end-to-end encryption. WhatsApp plans to send a formal legal demand to stop the spyware activity. The case highlights attackers’ preference for deception over exploiting app flaws to gain device access.
Part of the PlainSec briefing for 2026-04-02