Digital threat mirrors WhatsApp and monitors Android cell phone screen with fake update

WhatsappWhatsapp

Whatsapp - Photo: JarTee / Shutterstock.com

New malicious software focused on mobile devices has raised alarms among digital security experts in recent weeks. The invading program acts silently and manages to take control of the device’s vital functions. The main tactic involves deceiving the phone owner with promises of network connection improvements.

Pesquisadores from the Italian organization Osservatorio Nessuno discovered the threat and named it Morpheus. The malicious code disguises itself as an operating system update or carrier configuration package. Once installed, the agent gains power to view the screen, record audio and link additional devices into messengers without the victim’s knowledge. The detailed report on the case revealed unusual methods of infection.

whatsapp – Samuel Boivin/Shutterstock.com

The social engineering behind the service outage

The attack begins in a way that deviates from the common pattern of randomly sent links. Telephony Operadoras participate in the first stage in some of the cases registered in Europa. Elas performs the cutting off of the specific target’s mobile internet access. Logo after the signal drops, the user receives a conventional text message.

The content of the message contains a link to a website that simulates the telecommunications operator’s official technical assistance. The user is left without a connection and tends to follow the guidance immediately. The fake page suggests installing an app to restore data service. The desperation for connectivity makes it easier for criminals to act.

The home app only works as a cargo carrier. Ele goes by the technical name of dropper and loads the primary installation package. The sole function of this first program is to prepare the ground for the main agent. Todo process exploits user trust in system maintenance tools. The transporter scans the environment, copies the necessary files, and requests initial permissions to perform automatic installation of the full malware.

Essa approach avoids the use of complex operating system security flaws. The method relies almost entirely on social engineering to work. Researchers classify the threat as low-cost spying software. The effectiveness lies in the psychological manipulation of the target at a time of technical vulnerability.

Controle system deep and privacy invasion

Depois installation is complete, the master agent enables the operating system’s accessibility services. Essa native tool was originally created to help people with motor or visual disabilities. The feature allows the system to read the screen content aloud and simulate touches. Morpheus claims to be a legitimate assistance tool for obtaining these critical permissions.

The rogue software also requests device administrator permission. Ele enables wireless debugging covertly. The program executes internal commands to silently grant all dangerous permissions without generating on-screen alerts. The code disables the camera and microphone indicator lights. The application prevents protection systems from working properly and adjusts battery settings to remain active in the background uninterruptedly.

The agent’s monitoring capabilities go far beyond simply collecting basic data. The technical report confirmed a series of invasive actions that completely compromise user privacy. Key functions identified include:

  • Captura real-time screen images during use.
  • Gravação continuous audio and video via microphone and camera.
  • Leitura of all messaging app notifications and content.
  • Vinculação of an extra device in the messenger with biometrics fraud.
  • Desativação complete system native privacy icons.
  • Execução of advanced commands for elevation of privileges on the device.
  • Persistência of the code even after the phone has been completely reset.
  • Technical Suporte for multiple models from different manufacturers.

Durante the hacking process, the malware displays fake update and reboot screens. The user observes a simulated progress bar and believes that the device is undergoing routine maintenance. The app performs actions in the background while the fake screen blocks the interaction. The program opens the messenger and adds a device controlled by the attacker invisibly.

Rastreamento points to legal interception company

The network infrastructure used by Morpheus points to a specific corporate origin. The data directs to the Intelligence IPS. The Italian company has more than three decades of experience in the legal interception technology market. The company’s focus is on providing tools for police forces and government intelligence agencies. The organization operates in more than twenty countries and lists several European public security bodies as official clients.

The malware’s source code contains several expressions written in Italian. Analysts found cultural references typical of other similar software developments originating from the same country. Security researchers linked internet protocol addresses and structural components to domains associated with the surveillance company. The report also cites related companies that operate in the same telecommunications sector.

The digital espionage market is usually divided by the level of sophistication of the tools. The Morpheus requires direct action from the user to be installed on the device. Essa feature drastically reduces the tool development cost. The software maintains high effectiveness against specific targets in targeted surveillance contexts. The tactic differs from more expensive programs that infect the cell phone without any interaction from the victim.

Estratégias risk protection and mitigation

Especialistas in information security recommend extreme caution with links received via text messages. The main guideline is to never install applications that arrive through unofficial channels. Atualizações legitimate operating system and application applications must occur exclusively through official software stores. The device’s own settings menu is the only safe way to seek network improvements.

Users can check accessibility permissions and device administrators in advanced settings. Unknown Aplicativos that have wide screen access or permission to run unrestricted in the background deserve extra attention and immediate removal. Manter operating system always in the latest version helps limit privilege elevation techniques exploited by criminals.

Internal malicious agent management uses sequential workflows to bypass defenses. The program overlays fake interfaces over any open application. The code adapts its actions according to the device manufacturer to ensure operation. The discovery reinforces global discussions about the use of surveillance tools by governments. The case also raises debates about the need for transparency from telephone operators when they interrupt services in a targeted manner.