The Sri Lanka Computer Emergency Readiness Team (SLCERT) has warned that a newly identified “zero-click” WhatsApp account takeover attack is targeting iPhones running vulnerable versions of iOS, letting attackers seize accounts without the victim doing anything at all.
Several people, including members of the media and the business community, have complained to SLCERT about the attack, indicating the threat has reached Sri Lankan users rather than being confined overseas.
How it works
Unlike conventional WhatsApp scams, the attack requires no clicking of a malicious link and no scanning of a QR code. According to a forensic investigation by an Italian security firm cited by SLCERT, attackers may be exploiting a combination of vulnerabilities affecting the synchronisation of linked devices.
The attack is believed to affect devices running iOS versions below 16.7.12.
Victims reported unauthorised WhatsApp messages sent from their accounts requesting money transfers. In some cases no suspicious devices appeared under WhatsApp’s linked-device settings, making the takeover harder to detect. Attackers also took control of administrator privileges in WhatsApp groups run by the victims, SLCERT said.
What users are advised to do
SLCERT advised users to:
- Update iOS immediately
- Install the latest version of WhatsApp
- Enable two-step verification and the chat lock feature
- Verify any unusual financial request through a separate, trusted communication channel
Security experts said the incident reflects the growing use of zero-click techniques, which are considerably more sophisticated than the QR-code phishing that has driven most previous WhatsApp account thefts in Sri Lanka.
Anyone who believes their account has been compromised should report it to Sri Lanka CERT.
Sources: Ada Derana, Daily Mirror.