logo

Nice chatting with you: what connects cheap Android smartphones, WhatsApp and cryptocurrency theft?

ID: 76654334-2a4d-5f5e-a98e-ab59bb6a9848

STIX ID: report--76654334-2a4d-5f5e-a98e-ab59bb6a9848

Feed Name: Dr.Web News

Threat Score
75/100

Date Published: 2025-04-14

Date Updated: 2026-04-27

...
...

**Executive summary:** Doctor Web analysts discovered a widespread campaign (Shibai) in which low-end Android phones were shipped with a trojanized WhatsApp using LSPatch; the malware hijacks updates, monitors and replaces Tron/Ethereum wallet addresses (clipboard clipping), exfiltrates chats and wallet mnemonic screenshots, and is managed via >60 C2 servers and ~30 distribution domains with wallets observed holding up to ~$1M.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.