WhatsApp spam on the rise

Posted by   Virus Bulletin on   Jan 16, 2015

End-to-end encryption makes spam filtering more difficult.

Spam sent through the WhatsApp messaging service is on the rise, mobile security firm AdaptiveMobile reports.

This news should come as little surprise: any means by which messages can be spread quickly and cheaply has always been attractive to spammers, be that email, website comments or Twitter mentions. And just as many users have started to use WhatsApp and other OTT messaging apps as a replacement for SMS, so have spammers. Google searches for 'WhatsApp spam' have risen in recent years, just as searches for 'SMS spam' have decreased.

AdaptiveMobile's Cathal McDaid also points to a recently implemented anti-spam law in India, which made the sending of SMS spam illegal. As a consequence, the amount of SMS spam in India dropped by 97% in 2014 alone, and services have sprung up in the country that allow people to send bulk WhatsApp messages for very little cost.

What makes this particularly interesting is that WhatsApp is in the process of rolling out end-to-end encryption for all its users (much to the chagrin of the UK prime minister).

This means that WhatsApp, or its parent company Facebook, can see who is sending messages to whom, but it can't see what is actually inside the messages. The firm could thus stop someone from sending too many messages (thus driving up the cost for spammers), but it couldn't even detect a large number of (compromised) devices sending the very same message — which is a pretty good indicator of an ongoing spam campaign.

Of course, it would still be possible for the WhatsApp app, or a third-party anti-spam app running on the device, to check the content of a message and block it if it is deemed spam. But sending parts of messages, such as URLs, to a central server to look for patterns and check these against blacklists - an important technique in the filtering of email spam - would give away essential information about the messages to third parties.

I applaud WhatsApp's decision to roll out end-to-end encryption and hope many other companies will follow suit. But, as with just about any measure that improves security and/or privacy, it comes at a cost. We'll just have to become a bit more inventive in our fight against spam. And perhaps, if attempts to make more users use email encryption finally become successful, we will be able to use the lessons learned fighting WhatsApp spam to fight email spam in this much more restrictive environment.

Posted on 16 January 2015 by Martijn Grooten

twitter.png
fb.png
linkedin.png
hackernews.png
reddit.png

 

Latest posts:

VB2019 conference programme announced

VB is excited to reveal the details of an interesting and diverse programme for VB2019, the 29th Virus Bulletin International Conference, which takes place 2-4 October in London, UK.

VB2018 paper: Under the hood - the automotive challenge

Car hacking has become a hot subject in recent years, and at VB2018 in Montreal, Argus Cyber Security's Inbar Raz presented a paper that provides an introduction to the subject, looking at the complex problem, examples of car hacks, and the…

VB2018 paper and video: Android app deobfuscation using static-dynamic cooperation

Static analysis and dynamic analysis each have their shortcomings as methods for analysing potentially malicious files. Today, we publish a VB2018 paper by Check Point researchers Yoni Moses and Yaniv Mordekhay, in which they describe a method that…

VB2019 call for papers closes this weekend

The call for papers for VB2019 closes on 17 March, and while we've already received many great submissions, we still want more!

Registration open for VB2019 ─ book your ticket now!

Registration for VB2019, the 29th Virus Bulletin International Conference, is now open, with an early bird rate available until 1 July.

We have placed cookies on your device in order to improve the functionality of this site, as outlined in our cookies policy. However, you may delete and block all cookies from this site and your use of the site will be unaffected. By continuing to browse this site, you are agreeing to Virus Bulletin's use of data as outlined in our privacy policy.