HomeSecurityWhatsApp: Italian spyware company created fake iOS version

WhatsApp: Italian spyware company created fake iOS version

WhatsApp informed about 200 users, mostly in Italy , that they were tricked into installing a fake version of the app , which was government spyware .

WhatsApp spyware

The fake WhatsApp app was built by SIO, an Italian surveillance technology company that develops spyware for law enforcement and intelligence agencies, through its subsidiary ASIGINT.

WhatsApp said it identified the affected users, disconnected them from their accounts, warned them about the privacy risks, and urged them to delete the fake app and install the official app from a trusted source. The company told TechCrunch that it plans to send a formal legal demand to the SIO to stop any related malicious activity.

This is not the first time spyware has targeted WhatsApp

The revelation, first reported by Italian newspaper La Repubblica and news agency ANSA, marks the second time WhatsApp has publicly named a spyware vendor operating against its users in Italy. In early 2025, WhatsApp informed about 90 users, including journalists and pro-immigration activists, that they had been targeted by Paragon Solutions, an American-Israeli surveillance company whose flagship product, Graphite, was developed by Italy’s internal and external intelligence services.

See also: “WhatsApp malware” campaign uses malicious VBS files

This revelation caused a political crisis in Rome. Italy's parliamentary intelligence oversight committee, COPASIR, confirmed the use of Graphite and found that seven Italians had been targeted.

Paragon subsequently severed ties with Italian spy agencies after the government refused to confirm whether the spyware had been used against a specific journalist, Francesco Cancellato from the news website Fanpage.

WhatsApp: Italian spyware company created fake iOS version

How does the spyware work in the new campaign?

SIO’s spyware operates through a different model. The malware, identified in its code as Spyrtacus, is embedded in fake apps designed to look like legitimate software. Researchers have found 13 different samples of Spyrtacus dating back to 2019, with the most recent one circulating since late 2024. Previous versions disguised themselves as Android apps from Italian mobile carriers TIM, Vodafone, and WINDTRE (as well as previous fake versions of WhatsApp itself).

TechCrunch first uncovered SIO’s distribution campaign in February 2025. The latest operation, targeting iPhones, represents an extension of the tactic into the Apple ecosystem. Once installed, Spyrtacus can steal text messages, chat histories, and call logs, as well as record audio and video directly from the device’s microphone and camera.

The delivery mechanism is as revealing as the malware itself. In Italy, authorities typically secure cooperation from mobile phone providers, who send phishing links to their own customers on behalf of law enforcement. The target receives what appears to be a routine update notification from their provider and is asked to install what appears to be a standard WhatsApp update.

The Italian justice ministry has maintained a catalogue and price list showing how authorities can force telecom companies to send such messages, a system that essentially turns the mobile phone network itself into a distribution channel for state surveillance.

See also: FBI: Russian hackers target Signal and WhatsApp accounts

The cost of renting spyware in Italy is extremely low: as of late 2022, law enforcement authorities could access these tools for just 150 euros per day, without the large initial acquisition costs that usually limit deployment in other countries.

The spread of spyware in Italy and the new surveillance landscape

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Italy's position as a spyware hub is unusual among Western democracies. Companies such as Hacking Team, Cy4Gate, RCS Lab and Raxir are all based in the country, attracted by a legal framework that allows for extensive surveillance activities.

Italy appears to be developing into one of the most “active” areas of surveillance software use in Europe, according to Fabio Pietrosanti. As he points out, low costs and a more flexible regulatory framework have made such technologies accessible not only to national intelligence agencies, but also to local police authorities. The result is the formation of a broader and more decentralized surveillance ecosystem, where even municipal forces can commission citizen surveillance operations.

WhatsApp: Italian spyware company created fake iOS version

WhatsApp's stance and questions about goals

WhatsApp spokeswoman Margarita Franklin said the company prioritizes protecting users who may have been scammed by fake apps. However, it remains unclear whether the roughly 200 users affected include journalists or members of civil society. The lack of clarity on the possible involvement of Italian authorities or regulators leaves open critical questions of transparency and accountability.

Legal developments and pressure on the spyware industry

The legal framework surrounding commercial spyware has been changing rapidly in recent times. The NSO Group and Pegasus software was a turning point, as court decisions in the US — despite changes in compensation amounts — sent a clear message to curb such practices. WhatsApp’s parent company, Meta, is now stepping up its strategy, using legal action and public exposure as key deterrent tools.

At the same time, companies like Apple have taken a more active role in informing users, sending alerts about potential targeted attacks in dozens of countries. These mechanisms are now becoming the main way to uncover surveillance incidents, partially replacing the role of specialized cybersecurity researchers.

The "legal surveillance" market is booming

The global spyware market continues to grow rapidly, with estimates showing significant growth in the coming years. The most worrying element, however, is not the sophisticated Pegasus-type attacks, but the proliferation of simpler and cheaper tools based on phishing techniques. These tools drastically lower the technological and economic barrier to entry, allowing smaller services to gain capabilities that were previously reserved for high-level government agencies.

See also: New ways to protect against fraud on Facebook, WhatsApp and Messenger

Unlike previous spyware scandals, the SIO case highlights a different approach: leveraging social engineering. Instead of technically sophisticated attacks without user interaction, the model relies on deception — convincing the victim to install a fake application. The involvement of telecommunications providers, who are allegedly involved in the distribution of phishing messages, heightens concerns, as it turns the communication infrastructure itself into a surveillance tool.

WhatsApp: Italian spyware company created fake iOS version

The role of technology platforms as a counterweight

WhatsApp’s response, which includes publicly naming vendors, notifying users, and threatening legal action, highlights a new reality: technology platforms themselves are taking on the role of “regulator.” This is a development that would have seemed unthinkable a few years ago, but today it is emerging as one of the key mechanisms for controlling state surveillance.

For the users affected, the key question remains: who authorized the surveillance and on what legal basis? Although the Italian framework provides for judicial oversight, experience shows that control mechanisms often fail to prevent abuses. This case reinforces the sense that the problem is not limited to individual companies or incidents, but concerns a broader structural weakness.

Perhaps the most worrying conclusion is this: the threat no longer comes only from sophisticated cyberweapons, but from everyday practices that exploit users’ trust. In an environment where a simple message from a mobile provider can be the beginning of a breach, the line between legitimate surveillance and abuse is becoming increasingly blurred.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS