A fake WhatsApp that spied on everything — and most victims never knew
If someone handed you what looked exactly like WhatsApp but secretly recorded your calls, read your messages, and sent everything back to a surveillance company — would you notice? Probably not. That's precisely what happened to around 200 WhatsApp users, most of them in Italy, who were targeted in a sophisticated social engineering attack using a fake version of WhatsApp loaded with professional spyware.
Meta's security team caught it, identified the affected users, logged them out of their accounts, and sent them alerts warning about the privacy and security risk. The company also confirmed it's taking legal action against the Italian surveillance firm believed to be responsible.
This is not a story about a WhatsApp vulnerability or a hack of Meta's servers. The official WhatsApp app was not compromised. What happened is scarier in a different way — users were tricked into downloading a fake app that looked like WhatsApp, installed it themselves, and handed over full device access in the process.
Who made this fake WhatsApp?
The spyware is linked to an Italian company called SIO (full name: Sio Spa) operating through a subsidiary called ASIGINT. SIO describes itself as developing cyber-intelligence infrastructure and software, primarily for government clients. In plain terms: they build surveillance tools that governments pay for to monitor targets.
The spyware found inside the fake WhatsApp is identified in its code as "Spyrtacus" — a name that security researchers have tracked across multiple attack campaigns going back to at least 2019. Previous versions impersonated Android apps from Italian mobile carriers. The WhatsApp version represents an evolution of the same underlying surveillance toolkit.
This isn't a random criminal operation. Government-linked spyware companies — sometimes called "mercenary spyware" vendors — build these tools specifically to give law enforcement or intelligence agencies covert access to targets' devices. The Pegasus spyware from NSO Group is the most famous example. SIO's Spyrtacus operates in the same category: professional-grade surveillance software sold to governments, not script-kiddie malware.
How did users end up with fake WhatsApp on their phones?
The fake app was not distributed through official channels — not the Apple App Store, not the Google Play Store. It came through what investigators describe as "less controlled third-party channels." The exact distribution method hasn't been confirmed publicly, but a few possibilities exist based on how these attacks typically work.
Social engineering is the confirmed component. Victims were convinced — through some form of communication, whether email, SMS, or a link — to download and install a modified version of WhatsApp presented as legitimate. For iPhone users, this is technically harder than Android because iOS's closed ecosystem makes sideloading (installing apps outside the App Store) more difficult. However, it's not impossible through methods like enterprise certificate distribution, TestFlight abuse, or techniques enabled by recent regulatory changes in Europe that allow alternative app distribution on iOS.
For Android users, the attack surface is wider. Android has always allowed sideloading by enabling "Install from unknown sources" in settings. A convincingly designed installation prompt that mimics an official update could trick less technically aware users.
Meta was explicit: the official WhatsApp platform was not exploited. No server-side breach. No zero-day in the real app. The attack relied entirely on convincing humans to install the wrong thing — which, historically, is the most effective attack vector of all.
What could Spyrtacus do once installed?
Based on what's known about the Spyrtacus spyware family from previous documented attacks, a device infected with it effectively becomes an open book to the operator. The capabilities typically include reading messages across all messaging apps — WhatsApp, Telegram, Signal, iMessage — not just the fake WhatsApp. Call recording. Camera and microphone access. Location tracking. Contact list exfiltration. Photos and files. Essentially, anything on the device can be accessed.
This is what makes government-grade spyware different from ordinary malware. Consumer malware typically goes after banking credentials or shows ads. Government spyware is designed for complete surveillance of a target — everything they say, type, go, and do.
Meta logged the identified victims out of the fake app when the malicious client was discovered, which would have severed the connection between the spyware and its operators (for WhatsApp specifically). But whether the broader Spyrtacus infection persisted on affected devices after WhatsApp logout is unclear — spyware doesn't just disappear when one channel is closed.
Why does this matter for Indian WhatsApp users?
India has over 500 million WhatsApp users — the largest user base of any country. WhatsApp is how most Indians communicate for everything from family chats to business transactions. UPI payment confirmations go through WhatsApp. Business negotiations happen on WhatsApp. Personal conversations that people would consider completely private are on WhatsApp.
The current attack targeted users in Italy and is linked to a European surveillance company. Indian users are not the immediate target of this specific campaign. But the attack pattern — fake WhatsApp distributed through third-party channels to install surveillance software — is not Italy-exclusive. Variants of this attack have appeared in India before. In 2019, WhatsApp confirmed that Indian journalists and activists were targeted with Pegasus spyware through WhatsApp vulnerabilities. The methods evolve, but the goal is the same.
There is also a broader lesson for Indian users specifically: the WhatsApp ecosystem in India includes a significant amount of WhatsApp mods — GB WhatsApp, WhatsApp Plus, and similar modified versions that offer features the official app doesn't, like multiple accounts or different privacy settings. These mods are extremely popular in India, distributed through APK sites and Telegram channels rather than official stores. They are not vetted by Google or Meta, and some have historically contained malware or data-harvesting code. The fake WhatsApp in the Italy attack is a more sophisticated version of the same fundamental risk: unofficial WhatsApp builds that have been tampered with.
The legal action — and what it signals
Meta has confirmed it's sending a formal legal demand to SIO to cease malicious activity. This follows a pattern Meta has been establishing with mercenary spyware vendors. In 2021, Meta sued NSO Group (Pegasus) in US court. In early 2025, WhatsApp alerted around 90 Italian users about being targeted by Paragon Solutions' spyware. Now SIO is the named target.
These legal actions rarely result in spyware companies shutting down — they typically operate in jurisdictions where the legal exposure is manageable. But the public naming and legal action serves several purposes: it exposes the company's operations to public scrutiny, makes it harder for them to win new government clients, and creates precedent for holding surveillance vendors accountable for how their tools are used.
The broader industry dynamic here is significant. Government spyware companies have operated with near-impunity for years because their clients are governments, which provides legal cover. Meta's aggressive legal strategy is one of the few mechanisms applying real pressure to this market.
What you should do right now
For Indian WhatsApp users, three concrete actions:
First, make sure your WhatsApp is installed from the official source — App Store for iPhone, Google Play Store for Android. If you have any version of WhatsApp that was installed from a link, APK file, Telegram group, or any source other than the official stores, delete it and reinstall from the official store. This applies especially to GB WhatsApp, WhatsApp Plus, or any "modded" version.
Second, never install WhatsApp or any messaging app from a link someone sends you — even if the sender seems trustworthy. Legitimate WhatsApp updates come through the App Store or Play Store automatically, not through links.
Third, if you receive any notification from WhatsApp saying you've been logged out for security reasons, take it seriously. It may indicate your account was flagged for suspicious activity. Change your WhatsApp account phone number notification PIN (Settings → Account → Two-step verification) and review linked devices.
TamilTech's take
The WhatsApp spyware attack in Italy is a reminder that the most dangerous security threats aren't technical exploits — they're social engineering attacks that convince you to install something yourself. India's massive WhatsApp user base, combined with the widespread popularity of unofficial WhatsApp mods, creates a significant attack surface for this exact type of attack. GB WhatsApp and WhatsApp Plus are used by tens of millions of Indians who want features the official app doesn't offer. Every one of those installations is a potential vector for exactly what happened in Italy. The official app only. The official store only. Every single time.




Comments (0)
Be the first to comment!