Is WhatsApp Plus Malicious? A Review Using Static Analysis

Rizaldi Wahaz, Rakha Nadhifa Harmana, Amiruddin Amiruddin, Ardya Suryadinata · 2021

For cybersecurity activists, reviewing whether an application, including modified applications, is malicious or not is a challenging job. WhatsApp Plus is a messenger application modified from the official WhatsApp application. Comparing the source code of the WhatsApp Plus with the official WhatsApp is one way to review its security or malice. Considering that WhatsApp is very popular and has many users, the results of this investigation are very useful for users to avoid malicious applications. In this study, we have conducted an exploration of the source code of the WhatsApp and WhatsApp Plus applications to find out whether or not WhatsApp Plus has been inserted with malware, spyware, or other malicious code. The exploration used the static analysis method, where the source code of the two applications were decompiled, compared, and analyzed. The de-compilation is done using the MobSF tool and the comparison using the extension of Visual Studio Code called Compare Folders. The differences in the source code found are then analyzed for possible behavior to determine whether it can cause harm, for example stealing user credentials. Although no malicious code was found on WhatsApp Plus, in our study, users must stay alert since they remain vigilant in installing and using WhatsApp Plus because the developer may add malicious code to the next version update.

Read the paper · More papers on PaperTik