Wednesday, April 16, 2025
HomeAndroidBeware!! New Android Malware That Can Read Your WhatsApp Messages & Take...

Beware!! New Android Malware That Can Read Your WhatsApp Messages & Take Screen Shots

Published on

SIEM as a Service

Follow Us on Google News

A new Android malware that steals infected users WhatsApp messages and other sensitive data such as browsing history, photos.

This malware mainly developed to spying the targeted especially Android users and its unclear that what kind of surveillance attackers interested from the infected mobiles.

The source code of the malware associated file was found in Github page under the username called earthshakira.

- Advertisement - Google News

ESET researcher Lukas Stefanko discovered that the malware contains MainActivity.class that will start the OwnMe.class which will call the startService() Soon after onStartCommand() function is executed.

Malware authors using some persistence in order to hide their identity and avoid the suspicion by any security software.

Initially, the malware popups the toast( pop-up message) on the screen “Service started” which is the indication of the malware that still under development.

How Does it Steal WhatsApp Messages & Other Data

This malware called various different functionality to perform various malicious activities by delivering messages to the targeted victims.

Whenever targeted victims receiving the message that contains “WhatsApp”, then the malware called the uploadWhatsApp() function which is used to steal the  WhatsApp database using the following query: ipofthec2/db/upload_whatsapp.php and load to the attackers C2 server.

Same as if the message contains “browser history”, the element response from the JSON object v8 gets the return value of the function getHistory(). In this case, it steals currently only returns the saved bookmarks.

Similarly its using various other functions such as getContacts()., getCallLogs()., getBase64(v8.get(“path)), openCameraVideo() and other functions to steal the data such as Contacts, Fetch, Gallery, camera.

According to the gdatasoftware, This function returns the current battery level and the CPU usage. However, there is no implementation for a message check like with the commands above and hence that command is not actively used yet.

File Hashes:

SHA-256 4bed89b58c2ecf3455999dc8211c8a7e0f9e8950cb9aa83cd825b8372b1eaa3d

Also Read:

Newly Discovered Android Malware Stealing Data from Messaging Applications WhatsApp, Viber, Facebook

Dangerous Android Malware that Steals Banking Credentials, Call Forwarding, Keylogging, and Ransomware Activities

Android Malware in QR Code apps that Downloaded More than 500,000 times from Play Store

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

CISA Extend Funding to MITRE to Keep CVE Program Running

The Cybersecurity and Infrastructure Security Agency (CISA) has extended funding to the MITRE Corporation,...

Windows Task Scheduler Vulnerabilities Allow Attackers Gain Admin Account Control

New vulnerabilities in Windows Task Scheduler's schtasks.exe let attackers bypass UAC, alter metadata, modify...

Windows NTLM Vulnerability (CVE-2025-24054) Actively Exploit in the Wild to Hack Systems

A critical vulnerability in Microsoft Windows, identified as CVE-2025-24054, has been actively exploited in...

Server-Side Phishing Attacks Target Employee and Member Portals to Steal Login Credentials

Attackers have been deploying server-side phishing schemes to compromise employee and member login portals...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Beware! Online PDF Converters Tricking Users into Installing Password-Stealing Malware

CloudSEK's Security Research team, a sophisticated cyberattack leveraging malicious online PDF converters has been...

Chinese Hackers Unleash New BRICKSTORM Malware to Target Windows and Linux Systems

A sophisticated cyber espionage campaign leveraging the newly identified BRICKSTORM malware variants has targeted...

Malicious Macros Return in Sophisticated Phishing Campaigns

The cybersecurity landscape of 2025 is witnessing a troubling resurgence of malicious macros in...