{"id":350617,"date":"2025-10-21T07:10:00","date_gmt":"2025-10-21T14:10:00","guid":{"rendered":"https:\/\/cms-articles.softonic.io\/es\/?p=399671"},"modified":"2025-10-21T07:25:47","modified_gmt":"2025-10-21T14:25:47","slug":"be-careful-if-you-use-whatsapp-web-because-you-could-be-a-victim-of-spam","status":"publish","type":"post","link":"https:\/\/cms-articles.softonic.io\/en\/be-careful-if-you-use-whatsapp-web-because-you-could-be-a-victim-of-spam\/","title":{"rendered":"Be careful if you use WhatsApp Web, because you could be a victim of spam"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Cybersecurity researchers have discovered a coordinated campaign that uses 131 cloned WhatsApp Web automation extensions to spam users in Brazil. According to supply chain security company Socket, <strong>all of these extensions share the same code, design patterns, and infrastructure, and have approximately 20,905 active users<\/strong>.<\/p>\n\n\n<h2 class=\"wp-block-heading\">Some extensions that are not malicious, but can do harm<\/h2>\n\n\n<p class=\"wp-block-paragraph\">Extensions, which are not malware in the classical sense, are considered high risk due to their ability to abuse platform rules by injecting code directly into the WhatsApp Web page.<strong> This allows for the automation of mass message sending without user confirmation, with the aim of evading rate limits and WhatsApp&#8217;s anti-spam controls.<\/strong> The activity has been ongoing for at least nine months, with recent updates observed on October 17, 2025.<\/p>\n\n\n<p class=\"wp-block-paragraph\">Investigations reveal that most of the extensions have been published by \u201cWL Extens\u00e3o,\u201d suggesting that the differences in names and logos are linked to a franchise model. <strong>This model allows affiliates to flood the Chrome Web Store with various copies of the original extension offered by DBX Tecnologia<\/strong>. These extensions have the marketing of customer relationship management (CRM) tools, promoting sales optimization through WhatsApp Web.<\/p>\n\n\n<figure class=\"wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\">\n<iframe loading=\"lazy\" title=\"Message Privately\" width=\"840\" height=\"473\" src=\"https:\/\/www.youtube.com\/embed\/2TzXQWeW8Xs?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe>\n<\/div><\/figure>\n\n\n<p class=\"wp-block-paragraph\">DBX Tecnologia, the company behind these extensions, offers a white label program that promises affiliates significant recurring income by investing R$12,000. However, this procedure violates the spam and abuse policies of Google&#8217;s Chrome Web Store, which prohibits the publication of duplicate extensions. <strong>It has been observed that DBX Tecnologia even produces videos on YouTube about how to bypass WhatsApp&#8217;s anti-spam algorithms, indicating a conscious approach towards these practices<\/strong>.<\/p>\n\n\n<p class=\"wp-block-paragraph\">It can be suspected that this cloning and spam ecosystem has just begun to attract the attention of security companies, <strong>in a context where a large-scale campaign related to a WhatsApp worm distributing a banking Trojan known as Maverick has also been identified<\/strong>.<\/p>\n\n<div class=\"sc-card-program\">\r\n  <div class=\"sc-card-program__body\">\r\n    <div class=\"sc-card-program__row clearfix\">\r\n      <div class=\"sc-card-program__col-logo\">\r\n        <img decoding=\"async\" class=\"sc-card-program__img\" alt=\"WhatsApp\" src=\"https:\/\/images.sftcdn.net\/images\/t_app-icon-s\/p\/6b5a0468-96d1-11e6-bfc6-00163ec9f5fa\/2095394417\/whatsapp-logo\" width=\"100px\" height=\"100px\">\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-title\">\r\n        <span class=\"sc-card-program__title\">WhatsApp<\/span>\r\n        <a class=\"sc-card-program__button sc-card-program-internal\" href=\"https:\/\/whatsapp.softonic.com\/android\" target=\"_self\" rel=\"noopener noreferrer\">DOWNLOAD<\/a>\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-rating\">\r\n        <svg class=\"rating-score__content\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" version=\"1.1\" x=\"0\" y=\"0\" viewbox=\"0 0 50 50\" enable-background=\"new 0 0 50 50\" xml:space=\"preserve\"><path class=\"rating-score__background rating-score--good\" fill=\"none\" stroke-width=\"6\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><path class=\"rating-score__value rating-score__value--0\" fill=\"none\" stroke-width=\"6\" stroke-dashoffset=\"0\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><text class=\"rating-score__number\" content=\"\" text-anchor=\"middle\" transform=\"matrix(1 0 0 1 25 31.0837)\" data-auto=\"app-user-score\"><\/text><\/svg>\r\n      <\/div>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <span class=\"sc-card-program__description\"><\/span>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <img decoding=\"async\" class=\"sc-card-program__bigpic\" src=\"\" onerror=\"this.style.display='none'\">\r\n    <\/div>\r\n    <a class=\"sc-card-program__link track-link sc-card-program-internal\" href=\"https:\/\/whatsapp.softonic.com\/android\" target=\"_self\" rel=\"noopener noreferrer\"><\/a>\r\n  <\/div>\r\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Cybersecurity researchers have discovered a coordinated campaign that employs 131 cloned WhatsApp Web automation extensions to spam users in Brazil. According to supply chain security company Socket, all these extensions share the same code, design patterns, and infrastructure, and have approximately 20,905 active users. These extensions are not malicious, but they can cause harm. The extensions, which are not malware in the classic sense, are considered high risk due to their ability to abuse platform rules by injecting code directly into the WhatsApp Web page. [&hellip;]<\/p>\n","protected":false},"author":9318,"featured_media":350618,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wpcf-pageviews":0},"categories":[1015,11143],"tags":[17481,5605,3808,1752,1043,17482],"usertag":[],"vertical":[],"content-category":[7176],"class_list":["post-350617","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","category-softwaresecurity","tag-anti-spam","tag-ciberseguridad","tag-seguridad","tag-spam","tag-whatsapp","tag-whatsapp-web","content-category-seguridad-privacidad"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/350617","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/users\/9318"}],"replies":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/comments?post=350617"}],"version-history":[{"count":2,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/350617\/revisions"}],"predecessor-version":[{"id":350622,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/350617\/revisions\/350622"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media\/350618"}],"wp:attachment":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media?parent=350617"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/categories?post=350617"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/tags?post=350617"},{"taxonomy":"usertag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/usertag?post=350617"},{"taxonomy":"vertical","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/vertical?post=350617"},{"taxonomy":"content-category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/content-category?post=350617"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}