Fake WhatsApp Version for iPhone Apparently Made by an Italian Spyware Vendor to Target Individuals

The fake WhatsApp version for iPhone could be used by hackers to gain details of individuals through a specially crafted configuration file.

Advertisement
By Jagmeet Singh | Updated: 4 February 2021 11:52 IST
Highlights
  • WhatsApp for iPhone fake version could target specific individuals
  • It could be used to get user details of targeted people
  • WhatsApp is already suing NSO Group for abusing its infrastructure

WhatsApp has assured action against the fake version that has apparently been made by Cy4Gate

Photo Credit: Reuters

A fake version of WhatsApp for iPhone appears to have been made by Italian surveillance company Cy4Gate to target specific individuals, according to a report. It could have allowed hackers to gather information about targeted users by tricking them to install certain configuration files on their iPhone. The information that the hackers could obtain include — but not limited to — the Unique Device Identifier (UDID) as well as the International Mobile Equipment Identity (IMEI). In 2019, WhatsApp was exploited by a spyware developed by Israel's NSO Group that enabled entities to target journalists and human right activists in global regions including India.

Cybersecurity research lab at the University of Toronto, Citizen Lab, worked with Motherboard to find the fake version of WhatsApp for iPhone that has apparently been developed by Cy4Gate. The references of the counterfeit WhatsApp version emerged after security company ZecOps tweeted about the detection of attacks against users on the instant messaging app.

Advertisement

A site was found with domain config5-dati[.]com that was tricking visitors to install the fake app that was actually a special configuration file for the iPhone, Motherboard reported. It appeared to have been designed to gather information about the victims and send it back to the hackers.

Upon seeing the URL of the tricking site, Motherboard found multiple clusters of domains associated with the publicly shared link. Some variations of the original URL were also discovered. One of them was config1-dati[.]com that appeared to be a phishing page tricking individuals to install the fake version of WhatsApp. It looked legitimate, with WhatsApp branding and professional graphics, and provided instructions to the users on how to install a configuration file on the iPhone to get the fake version installed.

Advertisement

Citizen Lab researcher Bill Marczak noted that the configuration file provided by the phishing page was allowing the attacker to send device details including the UDID and IMEI to a server. The researchers, however, didn't find what other data the file could have provided from the user device.

There was no clear reference of whether the fake version of WhatsApp was linked with Cy4Gate that works with law agencies and the government in Italy. However, a set of domains was found that at one point shared an IP address with the config5-dati[.]com domain. That set brought notice to another set of domains that followed similar conventions, and one of them was registered to “cy4gate srl.” This suggested the linkage with the Italian surveillance company.

Advertisement

A WhatsApp spokesperson assured action against the fake version. “We strongly oppose abuse from spyware companies, regardless of their clientele. Modifying WhatsApp to harm others violates our terms of service. We have and will continue to take action against such abuse, including in court,” the spokesperson said, as quoted by Motherboard.

“To help keep chats safe, we recommend that people download WhatsApp from the app store for their phone's platform. In addition, we may temporarily ban people using modified WhatsApp clients we detect to help encourage people to download WhatsApp from an authoritative source,” the spokesperson added.

Advertisement

Facebook and WhatsApp — alongside other human rights groups — are currently fighting a legal battle with Israeli spyware maker NSO Group for allegedly reverse-engineering WhatsApp to spy on around 1,400 selected people worldwide. However, the latest finding suggests that NSO Group's Pegasus spyware wasn't the only option for entities to gain WhatsApp user details. Cy4Gate may have a similar system in place to acquire data by tricking some specific targeted individuals through the fake version of the app.


What will be the most exciting tech launch of 2021? We discussed this on Orbital, our weekly technology podcast, which you can subscribe to via Apple Podcasts, Google Podcasts, or RSS, download the episode, or just hit the play button below.

Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. New OTT Releases This Week : Dhurandhar 2, Maa Behen, The Pyramid Scheme, and More
  2. OnePlus 15, Nord 6, Pad 4 Receive Discounts During Community Sale 2026
  3. Xiaomi Pad 8 Price Increased: Here's How Much It Costs Now
  1. Sahara Meteorite May Be Fragment of a Lost Moon-Sized World, Study Suggests
  2. OpenAI Introduces Smarter ChatGPT Memory, Adds Dreaming Architecture
  3. Tecno Pova 8 India Launch Date Announced; Battery Size, Design, Colour Options Teased
  4. Samsung Reportedly Starts Internal Testing of Android 17-Based One UI 9 for Galaxy S25 Series
  5. Bybit Lists Western Union’s USDPT Stablecoin for Trading and Transfers
  6. Xiaomi Pad 8 Price Hiked in India: Here’s How Much It Costs Now
  7. Instagram Reels Influencing Nearly Half of Purchase Decisions in India, Meta Study Claims
  8. OnePlus Turbo 6X, OnePlus Turbo 6X Pro Colour Options, Price Range, Key Specifications Teased
  9. Sattendru Maarudhu Vaanilai Now Streaming Online: Where to Watch Jai’s Romantic Thriller Movie
  10. Asics GEL-Kayano 33 Launched in India With New Stability Tech, FluidSupport System
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.