logo

Arsink Spyware Posing as WhatsApp, YouTube, Instagram, TikTok Hits 143 Countries

ID: 7515e930-d121-5d4b-b0ec-b5e0b03a97a7

STIX ID: report--7515e930-d121-5d4b-b0ec-b5e0b03a97a7

Feed Name: HackRead

Threat Score
75/100

Date Published: 2026-01-30

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

Arsink is a widespread Android Remote Access Trojan (RAT) used in a global campaign that impersonates over 50 popular apps (WhatsApp, TikTok, etc.) and lures users via Telegram, Discord, and file-sharing sites; researchers found ~1,216 unique builds and ~45,000 infected devices across 143 countries. Once installed, Arsink runs persistent background services to exfiltrate data and enable remote control — including microphone recording, SMS and photo theft, contacts/call history access, location tracking, forced calls, and destructive wipes — with data sent to many backend channels (Firebase, Telegram bots, Google Drive, etc.).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.