WhatsApp spam on the rise

Posted by   Virus Bulletin on   Jan 16, 2015

End-to-end encryption makes spam filtering more difficult.

Spam sent through the WhatsApp messaging service is on the rise, mobile security firm AdaptiveMobile reports.

This news should come as little surprise: any means by which messages can be spread quickly and cheaply has always been attractive to spammers, be that email, website comments or Twitter mentions. And just as many users have started to use WhatsApp and other OTT messaging apps as a replacement for SMS, so have spammers. Google searches for 'WhatsApp spam' have risen in recent years, just as searches for 'SMS spam' have decreased.

AdaptiveMobile's Cathal McDaid also points to a recently implemented anti-spam law in India, which made the sending of SMS spam illegal. As a consequence, the amount of SMS spam in India dropped by 97% in 2014 alone, and services have sprung up in the country that allow people to send bulk WhatsApp messages for very little cost.

What makes this particularly interesting is that WhatsApp is in the process of rolling out end-to-end encryption for all its users (much to the chagrin of the UK prime minister).

This means that WhatsApp, or its parent company Facebook, can see who is sending messages to whom, but it can't see what is actually inside the messages. The firm could thus stop someone from sending too many messages (thus driving up the cost for spammers), but it couldn't even detect a large number of (compromised) devices sending the very same message — which is a pretty good indicator of an ongoing spam campaign.

Of course, it would still be possible for the WhatsApp app, or a third-party anti-spam app running on the device, to check the content of a message and block it if it is deemed spam. But sending parts of messages, such as URLs, to a central server to look for patterns and check these against blacklists - an important technique in the filtering of email spam - would give away essential information about the messages to third parties.

I applaud WhatsApp's decision to roll out end-to-end encryption and hope many other companies will follow suit. But, as with just about any measure that improves security and/or privacy, it comes at a cost. We'll just have to become a bit more inventive in our fight against spam. And perhaps, if attempts to make more users use email encryption finally become successful, we will be able to use the lessons learned fighting WhatsApp spam to fight email spam in this much more restrictive environment.

Posted on 16 January 2015 by Martijn Grooten

twitter.png
fb.png
linkedin.png
googleplus.png
reddit.png

 

Latest posts:

Where are all the ‘A’s in APT?

In a guest blog post by VB2018 gold partner Kaspersky Lab, Costin Raiu, Director of the company's Global Research and Analysis Team, looks critically at the 'A' in APT.

VB2018 preview: commercial spyware and its use by governments

Today, we preview three VB2018 presentations that look at threats against civil society in general and the use of commercial spyware by governments for this purpose in particular.

VB2018 preview: Wipers in the wild

Today we preview the VB2018 paper by Saher Naumaan (BAE Systems Applied Intelligence) on the use of wipers in APT attacks.

VB2018 preview: IoT botnets

The VB2018 programme is packed with a wide range of security topics featuring speakers from all around the world. Today we preview two of them: one by Qihoo 360 researchers on tracking variants of Mirai and one by researchers from Bitdefender on the…

VB2018: last-minute talks announced

We are excited to announce the final additions to the VB2018 programme in the form of 10 'last-minute' papers covering up-to-the-minute research and hot topics and two more invited talks.

We have placed cookies on your device in order to improve the functionality of this site, as outlined in our cookies policy. However, you may delete and block all cookies from this site and your use of the site will be unaffected. By continuing to browse this site, you are agreeing to Virus Bulletin's use of data as outlined in our privacy policy.