Android is the most versatile mobile operating system as it is able to run any type of file users might need. However, this very functionality can pose a security risk. This was the case where several WhatsApp users received malware files on the platform.
The malware files come in the form of fake Microsoft Excel documents which seem to be issued by the National Defense Agency or the National Investigation Agency. These organizations are part of the Indian government. If downloaded and opened on a user’s device, the documents trigger the installation of a malware.
This hidden malware is then able to collect all sort of user info like various app privileges and information, thus gaining control of the user’s device. From there, it’s even able to collect banking information as well as your passwords, depending on the type of activities you have used your phone for and what apps you have installed.
The recent reports which revealed the existence of this new exploit also stated that the two fake files are most commonly titled as “NIA-selection-order.xls” and “NDA-ranked-8th-toughest-College-in-the-world-to-get-into.xls”. Keep a look out for these names or any other suspicious and unrelated Excel files or anything that you didn’t expect to receive.
It’s also important to remember that the malware activates and begins to steal information as soon as you click the files in order to either download them, view them or edit them in any manner. This cannot be avoided no matter in what app you are trying to open the specified files. Many users have speculated that the malware files were intended for individuals who are actually part of the military or the government, or even those interested in international relations. However, nothing has been confirmed as of yet.
The malware has already been reported to government officials, but it’s very likely to continue to spread to unsuspecting WhatsApp users. Security experts also issued a warning stating that in these types of cases, other hackers could develop copycat malware which has the same function and be transmitted through the same method. As such, it’s recommended to maintain a state of permanent vigilance regarding the files you get, if you’re not keen on installing an antivirus app.
Image source: Flickr