logo

“GhostChat” Malware Targets WhatsApp Users with Hidden Payloads

ID: 162878ea-8953-5e7e-86b3-994bab72b8e1

STIX ID: report--162878ea-8953-5e7e-86b3-994bab72b8e1

Feed Name: Zimperium Blog

Threat Score
70/100

Date Published: 2026-02-09

Date Updated: 2026-05-01

...
...

GhostChat is a new Android malware family distributing malicious APKs that impersonate popular messaging apps (e.g., WhatsApp). After installation it injects into the messaging app process to intercept messages, steal credentials, and exfiltrate contact lists and media, leveraging its in-app operation to blend with legitimate activity and complicate detection; the report emphasizes verifying app sources, restricting permissions, and using real-time mobile anomaly detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.