Look out for WhatsApp ransomware
Posted: Monday, July 17, 2017
If you’ve been following our previous blogs on ransomware, you’ll be only too aware that hackers are always looking for new ways to extort money from users. Thankfully, Utilize security experts are also keeping a constant vigil for new vectors that attackers may be using to exploit our clients and we feed this information back to you when the threat is significant.
So let’s chat about WhatsApp.
With 1.2billion active users (figure for Feb 2017), WhatsApp is the biggest chat client in the world. Late last week, the organisation announced that users would be able to send any file via its app, which would include legitimate files like Office documents but also potentially malicious files such as APK’s. If you are unfamiliar with APK files, they are a format used by Android phones to distribute and install mobile apps.
As you may be aware, earlier this year on the dark web, ‘ransomware-as-a service’ was born. This means that a would-be criminal with very little technical knowledge could now pay to have a custom piece of ransomware written and deployed in order to attack people – and this includes ransomware for mobile phones, via apps.
Whilst some people have been infected via mobile ransomware, it has been relatively hard up until now to infect mobile users, since there was no easy way to deploy it. But with WhatsApp now offering the ability to send a file to your phone, a new potential delivery method has been made available.
In order to protect yourself from this risk, Utilize is recommending the following as a minimum:
- 1.Be wary of any file sent in WhatsApp that isn’t an image or video. Let’s face it, up until now, that’s all we have used it for. So always apply caution to a file that appears unusual. If opened, it could encrypt your phone and demand a ransom to restore access to your personal files.
- 2.Be aware of WhatsApp conversations from people you do not know. The chances are one of your contacts won’t be sending you ransomware, but people you don’t know will!
- 3.Ensure your mobile is up to date with the vendor’s operating system. This is very easy to do on the latest phones, most even advise you of new updates that are available.
- 4.Only download apps from Google Play store, and ensure ‘verify apps’ is activated. See below for iPhone and Android settings to check.
- 5.Ensure you regularly backup your mobile phone.
What protection is available for my phone?
Android smartphones do offer some basic built-in protection. To ensure “Verify Apps” is on, to your device settings, find ‘Google’ under Personal or Accounts. Tap on ‘Security’ and then ‘Verify Apps’. Activate ‘Scan device for security threats’.
Apple iPhones are slightly more protected as you only have the choice to install genuine apps from the AppStore. However be aware of spammy texts as these are sometimes used to infect iPhones via malicious clickable links.
Utilize is also a Sophos Platinum partner, and offers a wide range of security products to its customers. We would recommend Sophos mobile antivirus and Sophos Mobile Contro to secure your mobile from viruses and enable full mobile management and compliance, as well as offering ‘remote wipe’ should a phone be lost or stolen.
Our security team can also advise on other products to enhance your protection from the threat of ransomware – not just on your mobile phones but for your whole digital world. Please contact us for more information.











