Incident: Android WhatsApp 'Worm' Malware Scam Targeting Users for Ad Revenue

Published Date: 2021-01-29

Postmortem Analysis
Timeline 1. The software failure incident targeting Android users via a malicious app on WhatsApp was reported on January 29, 2021 [Article 109964]. Therefore, the software failure incident happened in January 2021.
System 1. Android operating system [109964] 2. WhatsApp messaging platform [109964]
Responsible Organization 1. Criminals who created the malicious software targeting Android users via WhatsApp [109964]
Impacted Organization 1. Android users were impacted by the software failure incident reported in Article 109964. The malicious software targeted Android users through a fake app distributed via WhatsApp, leading to potential exposure to scams, adware, and phishing attempts [109964].
Software Causes 1. The software cause of the failure incident was a piece of malicious software targeting Android users through a fake app distributed via WhatsApp, tricking users into downloading the app that then targets the devices of their friends [109964].
Non-software Causes 1. Lack of user awareness and caution when clicking on suspicious links and downloading apps from untrusted sources [109964] 2. Social engineering tactics used by criminals to trick users into granting permissions and downloading malicious apps [109964] 3. Potential for personal information and credentials theft due to users falling for adware subscription scams [109964]
Impacts 1. The software failure incident led to Android users being targeted by a malicious software 'worm' that tricked users into downloading a fake app via WhatsApp, potentially exposing them to ad bombardment, subscription scams, and the risk of personal information and bank details being stolen [109964]. 2. The incident caused the malware to automatically send messages to a person's contacts once an hour, potentially leading to the spread of the scam and increasing the likelihood of more users falling victim to the fake app [109964]. 3. The scam had the potential to steal personal information, credentials, and banking passwords, putting users at risk of financial fraud and privacy breaches [109964]. 4. The incident highlighted the importance of caution and vigilance when receiving links on any platform, especially those that appear unusual or from untrusted sources, to prevent falling victim to similar malware attacks in the future [109964].
Preventions 1. Only download apps from legitimate sources such as the official Play Store to prevent malware infections [109964]. 2. Avoid clicking on suspicious or unusual links, especially in messages from unknown sources, to prevent falling victim to phishing scams [109964]. 3. Be cautious and vigilant when receiving links on any platform that are unfamiliar or seem unusual to avoid potential malware attacks [109964].
Fixes 1. Users should only download apps from legitimate sources such as the official Google Play Store to avoid falling victim to malicious software like the 'worm' targeting Android users [109964]. 2. Users should be cautious when clicking on links in messages, especially those that seem unusual or from unknown sources, to prevent inadvertently downloading harmful apps [109964]. 3. It is essential to report suspicious messages and apps promptly to the relevant authorities or platforms to take action against such malicious activities and protect other users [109964].
References 1. WhatsApp spokesperson 2. Lukas Stefanko, a researcher at cybersecurity firm ESET 3. Ray Walsh, a technology expert at ProPrivacy 4. Jake Moore, a Cybersecurity Specialist at ESET 5. MailOnline

Software Taxonomy of Faults

Category Option Rationale
Recurring unknown The software failure incident described in the article [109964] is a new type of WhatsApp scam involving a malicious app targeting Android users. This specific incident does not mention any previous occurrences within the same organization or with its products and services (a) or at other organizations (b). Therefore, there is no information provided in the article to indicate that this incident has happened before either within the same organization or with other organizations.
Phase (Design/Operation) design (a) The software failure incident in the article is related to the design phase. The incident involves a piece of malicious software that tricks users into downloading a fake app via WhatsApp. The software requests users to enable various functions and permissions, activating a hidden capability to reply to WhatsApp messages with a link to a dodgy site. This design flaw allows the malware to spread and potentially steal personal information and bank details [109964]. (b) The software failure incident is not related to the operation phase.
Boundary (Internal/External) within_system, outside_system (a) within_system: The software failure incident described in the article is primarily due to a malicious app targeting Android users through WhatsApp. The malicious software, referred to as a 'worm,' tricks users into downloading a fake app that then targets the devices of their friends. The app requests various permissions and functions, enabling it to automatically reply to WhatsApp messages with a link to a dodgy site. This behavior is all contained within the software itself, indicating that the failure originates from within the system [Article 109964]. (b) outside_system: The incident also involves external factors such as criminal intent and phishing tactics. The scammers behind the malicious app aim to generate revenue through ad bombardment or subscription scams. Additionally, experts warn that the software could potentially be adapted to steal personal information and bank details, highlighting the external threat posed by cybercriminals [Article 109964].
Nature (Human/Non-human) non-human_actions, human_actions (a) The software failure incident in the article is primarily due to non-human actions, specifically the malicious software (worm) that tricks users into downloading a fake app and spreading through WhatsApp messages automatically without human intervention [Article 109964]. (b) However, human actions also play a role in this incident as users need to click on the malicious link and grant permissions for the worm to operate on their devices. Additionally, scammers create the fake app and phishing messages to deceive users [Article 109964].
Dimension (Hardware/Software) software (a) The software failure incident reported in the articles is not attributed to hardware issues. Instead, it is a case of malicious software targeting Android users through a fake app distributed via WhatsApp. The incident involves a worm that tricks users into downloading a fake app, which then sends out phishing messages and potentially steals personal information and bank details [Article 109964]. (b) The software failure incident is directly related to software issues. The malicious software, in the form of a worm, infects Android devices through a fake app distributed via WhatsApp. The software tricks users into enabling various functions and permissions, allowing it to send out phishing messages and potentially steal personal information and bank details. The incident highlights the importance of being cautious with app downloads and links received through messaging platforms to prevent falling victim to such software attacks [Article 109964].
Objective (Malicious/Non-malicious) malicious (a) The objective of the software failure incident was malicious, as it involved a piece of malicious software targeting Android users through a fake app distributed via WhatsApp. The software, referred to as a 'worm,' tricked users into downloading a fake app that could then target the devices of their friends. The scam aimed to bombard people with ads to generate revenue for criminals or to dupe individuals into signing up for a subscription service. Additionally, experts warned that the software could be adapted to steal personal information and bank details [Article 109964].
Intent (Poor/Accidental Decisions) poor_decisions (a) The intent of the software failure incident was primarily to trick Android users into downloading a fake app through a malicious 'worm' spread via WhatsApp. The fake app, named 'Huawei Mobile,' was designed by scammers to deceive users into signing up for a subscription service or clicking on ads, generating revenue for the criminals [109964]. The incident involved poor decisions made by the scammers to exploit users' trust in WhatsApp messages and the appearance of a fake Google Play Store to deceive them into downloading the malicious app.
Capability (Incompetence/Accidental) development_incompetence, accidental (a) The software failure incident can be attributed to development incompetence as the malicious software targeted Android users by tricking them into downloading a fake app via WhatsApp. The app, named 'Huawei Mobile,' was not a legitimate Huawei app but was created by scammers to deceive users [109964]. (b) The incident can also be categorized as accidental as users were unknowingly granting permissions to the malicious app, which then had the capability to auto-reply to WhatsApp messages and potentially steal personal information and bank details. The scam involved a convincing clone of the Google Play store, leading users to believe they were downloading a legitimate app [109964].
Duration temporary The software failure incident described in the article is more of a temporary nature. The malicious software, referred to as a 'worm,' targets Android users through a fake app distributed via WhatsApp messages. The worm infects a person's phone when they click on a malicious link and grant various permissions, enabling the software to automatically reply to WhatsApp messages with a link to a fake site [109964]. This incident is temporary as it relies on specific actions by users, such as clicking on the link and granting permissions, for the malware to spread and cause harm.
Behaviour value, other (a) crash: The software failure incident described in the article does not involve a crash where the system loses state and does not perform any of its intended functions [Article 109964]. (b) omission: The software failure incident does not involve the system omitting to perform its intended functions at an instance(s) [Article 109964]. (c) timing: The software failure incident does not involve the system performing its intended functions correctly, but too late or too early [Article 109964]. (d) value: The software failure incident involves the system performing its intended functions incorrectly by tricking users into downloading a fake app, sending phishing messages, and potentially stealing personal information and bank details [Article 109964]. (e) byzantine: The software failure incident does not involve the system behaving erroneously with inconsistent responses and interactions [Article 109964]. (f) other: The software failure incident involves the system behaving in a way not described in the options (a to e) by spreading a worm through WhatsApp messages, tricking users into downloading a malicious app, and potentially leading to adware subscription scams and fraud [Article 109964].

IoT System Layer

Layer Option Rationale
Perception None None
Communication None None
Application None None

Other Details

Category Option Rationale
Consequence property, theoretical_consequence The consequence of the software failure incident described in the articles is primarily related to potential harm and property loss. The malicious software targeted Android users through a WhatsApp scam, tricking them into downloading a fake app that could potentially lead to the theft of personal information and bank details [Article 109964]. The scam aimed to bombard people with ads to generate revenue for criminals or dupe them into signing up for a subscription service. Additionally, experts warned that the malware had the potential to steal personal information and credentials, leading to potential financial harm [Article 109964]. The software failure incident did not result in any reported deaths, physical harm, impact on basic needs, or significant delays. The primary consequences discussed were related to potential harm to individuals' personal information and financial loss due to the scam.
Domain information (a) The software failure incident reported in the article is related to the information industry, specifically targeting Android users through a malicious software that tricks users into downloading a fake app via WhatsApp [Article 109964].

Sources

Back to List