Reminder to @WhatsApp users that downloading a fake or modified version of WhatsApp is never a good idea. These apps sound harmless but they may work around WhatsApp privacy and security guarantees. A thread:
— Will Cathcart (@wcathcart) July 11, 2022
Cathcart said that his team had discovered hidden malware within apps that can be downloaded outside of Google's Play Store from a developer called HeyMods. This developer produces a series of knock-off apps and one among them is called Hey WhatsApp.
The apps promise new features not found in the official versions to lure people in, and then steal their personal information without them realizing it. Cathcart said that his team had alerted Google and updated them with the information they found.
He said that Google Play Store can now detect and block previously downloaded "malicious fake versions" of WhatsApp, and advised users to not stray far from Android's official app store.
Cathcart encouraged users to report any instances of friends or family members using malicious apps, and to encourage them to, "only use WhatsApp from a trusted app store" or the Meta-owned company's official website.
"Mobile phone malware is a pernicious threat that must be countered and the security community continues to develop new ways to prevent it from spreading," Cathcart wrote in his tweet.