A sophisticated cyberattack targeting WhatsApp accounts on older iPhones has reportedly affected users in Sri Lanka, prompting complaints to the Sri Lanka Computer Emergency Readiness Team (Sri Lanka CERT).
Unlike common online scams that rely on victims opening links or scanning fraudulent QR codes, the reported attack can compromise an account without any action from the user. The threat is believed to exploit weaknesses in the way WhatsApp handles synchronization with linked devices.
Several people from Sri Lanka’s media and business sectors have reportedly encountered or raised concerns about similar incidents, suggesting that the threat has reached local users.
A forensic examination by an Italian cybersecurity company found that compromised WhatsApp accounts were allegedly used to contact other people with fraudulent requests for money. In some cases, victims reportedly did not see unfamiliar devices in their WhatsApp linked-device lists, potentially allowing the unauthorized access to go unnoticed.
The attackers have also reportedly gained administrator control of WhatsApp groups after taking over individual accounts.
The incidents are believed to involve iPhones operating on iOS versions older than 16.7.12, underscoring the security risks associated with using outdated software.
Cybersecurity experts are urging iPhone users to install the latest available iOS and WhatsApp updates. They also recommend activating WhatsApp’s two-step verification and Chat Lock features as additional security measures.
Users have further been advised to independently confirm any unexpected request for money or sensitive information, even if the message appears to have been sent by someone they know.
The reported incidents highlight how increasingly sophisticated zero-click attacks are being used by financially motivated cybercriminals and reinforce the need for users to keep both their devices and applications updated.
Leave your comments
Login to post a comment
Post comment as a guest