An unofficial version of the popular WhatsApp messaging app called YoWhatsApp has been observed deploying an Android trojan known as Triada.
The goal of the malware is to steal the keys that "allow the use of a WhatsApp account without the app," Kaspersky said in a new report. "If the keys are stolen, a user of a malicious WhatsApp mod can lose control over their account."
YoWhatsApp offers the ability for users to lock chats, send messages to unsaved numbers, and customize the app with a variety of theming options. It's also said to share overlaps with other modded WhatsApp clients such as FMWhatsApp and HeyMods.
The Russian cybersecurity company said it found the malicious functionality in YoWhatsApp version 22.214.171.124.
Typically spread through fraudulent ads on Snaptube and Vidmate, the app, upon installation, requests the victims to grant it permissions to access SMS messages, enabling the malware to enroll them to paid subscriptions without their knowledge.
A successful theft of the keys can lead to a total compromise of the account, allowing the adversary to access chat messages and even impersonate the victim to send malspam and conduct financial fraud.
The development comes amid Meta Platforms filing a lawsuit against three developers in China and Taiwan for distributing unofficial WhatsApp apps, including HeyMods, that resulted in the compromise of over one million user accounts.
The findings also arrive a little over a year after threat actors were found delivering the Triada malware through FMWhatsApp.
"Cybercriminals are increasingly using the power of legitimate software to distribute malicious apps," the researchers pointed out. "This means that users who choose popular apps and official installation sources, may still fall victim to them."