‹ Back to Home

Fake WhatsApp With Government Spyware Found on iPhones — Meta Is Warning 200 Users

Someone built a fake version of WhatsApp loaded with government-grade spyware, tricked around 200 people into installing it, and got away with full access to their devices. Meta has now identified the victims and warned them. Here's exactly what happened, who made this spyware, and what every WhatsApp user needs to know.

Keerthika 7 min read 690
Follow on Google
Updated 5 months ago
Scam Alerts Fake WhatsApp With Government Spyware Found on iPhones — Meta Is Warning 200 Users 7 min left Follow on Google
Fake WhatsApp With Government Spyware Found on iPhones — Meta Is Warning 200 Users

TamilTech AI summary

Meta recently warned about 200 WhatsApp users, mostly in Italy, who were tricked into installing a fake WhatsApp app packed with professional spyware called Spyrtacus from an Italian surveillance firm called SIO, and the company logged those people out and is taking legal action. This was not a hack of real WhatsApp or Meta’s servers—people were socially engineered into sideloading a lookalike app from unofficial channels that then gave operators deep access to messages, calls, camera, mic, location, and more. It matters because this is government-grade “mercenary spyware,” in the same category as tools like Pegasus, and the same fake-app pattern could hit other countries, including India where hundreds of millions rely on WhatsApp and unofficial mods like GB WhatsApp are common. You should only ever install WhatsApp from the official App Store or Google Play Store, never from links, APKs, Telegram channels, or modded builds, and treat any unexpected security logout from WhatsApp as a serious warning. Turn on two-step verification, review linked devices, and stick to the official app every single time so you do not hand over your whole phone the way those victims did.

  • Italian spyware firm SIO built fake WhatsApp with government-grade 'Spyrtacus' spyware — Meta identified ~200 victims, logged them out and warned them
  • Not a WhatsApp platform hack — users were socially engineered into installing unofficial fake app through third-party channels; official app is safe
  • India risk: 500M+ WhatsApp users; GB WhatsApp/WhatsApp Plus mods used by tens of millions are same attack vector — always use official Play Store/App Store version

AI-assisted summary, checked by the TamilTech editorial team.

0:00
0:00
🔒 Listen is for subscribers. Subscribe

A fake WhatsApp that spied on everything — and most victims never knew

If someone handed you what looked exactly like WhatsApp but secretly recorded your calls, read your messages, and sent everything back to a surveillance company — would you notice? Probably not. That's precisely what happened to around 200 WhatsApp users, most of them in Italy, who were targeted in a sophisticated social engineering attack using a fake version of WhatsApp loaded with professional spyware.

Meta's security team caught it, identified the affected users, logged them out of their accounts, and sent them alerts warning about the privacy and security risk. The company also confirmed it's taking legal action against the Italian surveillance firm believed to be responsible.

This is not a story about a WhatsApp vulnerability or a hack of Meta's servers. The official WhatsApp app was not compromised. What happened is scarier in a different way — users were tricked into downloading a fake app that looked like WhatsApp, installed it themselves, and handed over full device access in the process.

Who made this fake WhatsApp?

The spyware is linked to an Italian company called SIO (full name: Sio Spa) operating through a subsidiary called ASIGINT. SIO describes itself as developing cyber-intelligence infrastructure and software, primarily for government clients. In plain terms: they build surveillance tools that governments pay for to monitor targets.

The spyware found inside the fake WhatsApp is identified in its code as "Spyrtacus" — a name that security researchers have tracked across multiple attack campaigns going back to at least 2019. Previous versions impersonated Android apps from Italian mobile carriers. The WhatsApp version represents an evolution of the same underlying surveillance toolkit.

This isn't a random criminal operation. Government-linked spyware companies — sometimes called "mercenary spyware" vendors — build these tools specifically to give law enforcement or intelligence agencies covert access to targets' devices. The Pegasus spyware from NSO Group is the most famous example. SIO's Spyrtacus operates in the same category: professional-grade surveillance software sold to governments, not script-kiddie malware.

How did users end up with fake WhatsApp on their phones?

The fake app was not distributed through official channels — not the Apple App Store, not the Google Play Store. It came through what investigators describe as "less controlled third-party channels." The exact distribution method hasn't been confirmed publicly, but a few possibilities exist based on how these attacks typically work.

Social engineering is the confirmed component. Victims were convinced — through some form of communication, whether email, SMS, or a link — to download and install a modified version of WhatsApp presented as legitimate. For iPhone users, this is technically harder than Android because iOS's closed ecosystem makes sideloading (installing apps outside the App Store) more difficult. However, it's not impossible through methods like enterprise certificate distribution, TestFlight abuse, or techniques enabled by recent regulatory changes in Europe that allow alternative app distribution on iOS.

For Android users, the attack surface is wider. Android has always allowed sideloading by enabling "Install from unknown sources" in settings. A convincingly designed installation prompt that mimics an official update could trick less technically aware users.

Meta was explicit: the official WhatsApp platform was not exploited. No server-side breach. No zero-day in the real app. The attack relied entirely on convincing humans to install the wrong thing — which, historically, is the most effective attack vector of all.

What could Spyrtacus do once installed?

Based on what's known about the Spyrtacus spyware family from previous documented attacks, a device infected with it effectively becomes an open book to the operator. The capabilities typically include reading messages across all messaging apps — WhatsApp, Telegram, Signal, iMessage — not just the fake WhatsApp. Call recording. Camera and microphone access. Location tracking. Contact list exfiltration. Photos and files. Essentially, anything on the device can be accessed.

This is what makes government-grade spyware different from ordinary malware. Consumer malware typically goes after banking credentials or shows ads. Government spyware is designed for complete surveillance of a target — everything they say, type, go, and do.

Meta logged the identified victims out of the fake app when the malicious client was discovered, which would have severed the connection between the spyware and its operators (for WhatsApp specifically). But whether the broader Spyrtacus infection persisted on affected devices after WhatsApp logout is unclear — spyware doesn't just disappear when one channel is closed.

Why does this matter for Indian WhatsApp users?

India has over 500 million WhatsApp users — the largest user base of any country. WhatsApp is how most Indians communicate for everything from family chats to business transactions. UPI payment confirmations go through WhatsApp. Business negotiations happen on WhatsApp. Personal conversations that people would consider completely private are on WhatsApp.

The current attack targeted users in Italy and is linked to a European surveillance company. Indian users are not the immediate target of this specific campaign. But the attack pattern — fake WhatsApp distributed through third-party channels to install surveillance software — is not Italy-exclusive. Variants of this attack have appeared in India before. In 2019, WhatsApp confirmed that Indian journalists and activists were targeted with Pegasus spyware through WhatsApp vulnerabilities. The methods evolve, but the goal is the same.

There is also a broader lesson for Indian users specifically: the WhatsApp ecosystem in India includes a significant amount of WhatsApp mods — GB WhatsApp, WhatsApp Plus, and similar modified versions that offer features the official app doesn't, like multiple accounts or different privacy settings. These mods are extremely popular in India, distributed through APK sites and Telegram channels rather than official stores. They are not vetted by Google or Meta, and some have historically contained malware or data-harvesting code. The fake WhatsApp in the Italy attack is a more sophisticated version of the same fundamental risk: unofficial WhatsApp builds that have been tampered with.

Meta has confirmed it's sending a formal legal demand to SIO to cease malicious activity. This follows a pattern Meta has been establishing with mercenary spyware vendors. In 2021, Meta sued NSO Group (Pegasus) in US court. In early 2025, WhatsApp alerted around 90 Italian users about being targeted by Paragon Solutions' spyware. Now SIO is the named target.

These legal actions rarely result in spyware companies shutting down — they typically operate in jurisdictions where the legal exposure is manageable. But the public naming and legal action serves several purposes: it exposes the company's operations to public scrutiny, makes it harder for them to win new government clients, and creates precedent for holding surveillance vendors accountable for how their tools are used.

The broader industry dynamic here is significant. Government spyware companies have operated with near-impunity for years because their clients are governments, which provides legal cover. Meta's aggressive legal strategy is one of the few mechanisms applying real pressure to this market.

What you should do right now

For Indian WhatsApp users, three concrete actions:

First, make sure your WhatsApp is installed from the official source — App Store for iPhone, Google Play Store for Android. If you have any version of WhatsApp that was installed from a link, APK file, Telegram group, or any source other than the official stores, delete it and reinstall from the official store. This applies especially to GB WhatsApp, WhatsApp Plus, or any "modded" version.

Second, never install WhatsApp or any messaging app from a link someone sends you — even if the sender seems trustworthy. Legitimate WhatsApp updates come through the App Store or Play Store automatically, not through links.

Third, if you receive any notification from WhatsApp saying you've been logged out for security reasons, take it seriously. It may indicate your account was flagged for suspicious activity. Change your WhatsApp account phone number notification PIN (Settings → Account → Two-step verification) and review linked devices.

TamilTech's take

The WhatsApp spyware attack in Italy is a reminder that the most dangerous security threats aren't technical exploits — they're social engineering attacks that convince you to install something yourself. India's massive WhatsApp user base, combined with the widespread popularity of unofficial WhatsApp mods, creates a significant attack surface for this exact type of attack. GB WhatsApp and WhatsApp Plus are used by tens of millions of Indians who want features the official app doesn't offer. Every one of those installations is a potential vector for exactly what happened in Italy. The official app only. The official store only. Every single time.

Get tomorrow’s tech news on WhatsApp

One short update a day, free. Follow the TamilTech channel.

What do you think?

people reacted

Keerthika

TamilTech editorial team · 3,344 articles

Keerthika is an editor at TamilTech, the Tamil and English technology publication founded by Praveen Kumar S. She covers AI, smartphones, gadgets, EVs, startups and cybersecurity i...

More from Keerthika

Ask TamilTech on WhatsApp

Tech doubt? Ask in Tamil or English — our WhatsApp assistant answers from TamilTech articles in seconds.

Related stories

Comments (0)

| Supports **bold**, *italic*, `code`

Be the first to comment!

Next story Truecaller just put scam intel on the open web
Tamiltech

Tamiltech

Install app for faster access

Earn XP 🏆
WhatsApp
Notifications