
The Sri Lanka Computer Emergency Readiness Team (SLCERT) has stated that a newly identified zero-click WhatsApp account takeover attack is reportedly targeting iPhones running vulnerable iOS 16 versions, allowing attackers to gain access to WhatsApp accounts without requiring any user interaction.
According to SLCERT, several individuals, including members of the media and business community, have complained to the Sri Lanka CERT about the attack, demonstrating that this zero-click WhatsApp breach is also taking place in Sri Lanka.
According to a forensic investigation by an Italian security firm, attackers may be exploiting a combination of vulnerabilities affecting linked device synchronization.
Victims reported unauthorized WhatsApp messages requesting money transfers, while no suspicious linked devices appeared in their account settings. Further, the hackers took over the WhatsApp groups admin by the victims, the statement said.
SLCERT said the attack is believed to affect devices running iOS versions below 16.7.12 and demonstrates a more sophisticated method than traditional QR-code phishing attacks.
SLCERT has advised users to update iOS immediately, install the latest version of WhatsApp, enable two-step verification and chat lock features, and verify any unusual financial requests through a trusted communication channel.
Security experts have also warned that the incident reflects the increasing use of zero-click exploitation techniques by financially motivated cybercriminals, highlighting the importance of keeping mobile devices and applications fully updated.





















