Sri Lanka's Computer Emergency Readiness Team (CERT) has issued an urgent warning to iPhone users across the country regarding a newly identified and highly sophisticated zero-click WhatsApp account takeover attack. Unlike conventional cyber threats that require victims to click a malicious link or download a suspicious file, this particular attack is alarmingly dangerous because it requires absolutely no action from the targeted user. The attack can silently compromise a WhatsApp account, leaving victims completely unaware that their private conversations, contacts, and sensitive data have been exposed to malicious actors.
What Is a Zero-Click Attack?
A zero-click attack is one of the most dangerous forms of cyber exploitation in the modern digital landscape. As the name suggests, the attack does not require the victim to interact with any content β no clicking, no downloading, no responding. The malicious code exploits vulnerabilities within an application or operating system and executes automatically upon receiving a specially crafted message or data packet. In this case, the vulnerability is being actively exploited within WhatsApp on iPhone devices, making it particularly concerning for iOS users in Sri Lanka who rely heavily on the messaging platform for both personal and professional communication.
Security researchers have noted that zero-click vulnerabilities are often favored by sophisticated threat actors, including state-sponsored groups, because they leave minimal traces and are extremely difficult to detect or prevent through standard user behavior. Once a device is compromised, attackers can gain full access to a victim's WhatsApp account, including message history, media files, and contact lists.
Sri Lanka CERT's Official Warning
Sri Lanka CERT, the national authority responsible for cybersecurity incident response and awareness, confirmed the threat following reports of suspicious account activity linked to this attack vector. The organization has urged all iPhone users in Sri Lanka who use WhatsApp to take immediate precautionary steps to protect their accounts and personal data. CERT has also indicated that it is actively monitoring the situation and coordinating with relevant international cybersecurity agencies to better understand the scope and origin of the attack.
The warning comes at a time when Sri Lanka has seen a steady rise in cybercrime incidents, with messaging platforms increasingly becoming prime targets for threat actors seeking to exploit both individual users and organizations. CERT's timely advisory reflects a growing recognition that public awareness is one of the most effective tools in combating sophisticated cyber threats.
How the Attack Works
While full technical details are still being investigated, preliminary findings suggest that the attack exploits a flaw in how WhatsApp processes certain incoming data on iOS devices. When a specially crafted packet is sent to the target's WhatsApp account, the vulnerability is triggered automatically, allowing the attacker to gain unauthorized access without the user ever opening the app or interacting with the message. The attacker can then take over the account, lock out the legitimate user, and use the compromised account to spread the attack further to other contacts.
This method of propagation is particularly concerning because it means the attack can spread rapidly through trusted contact networks, making victims more likely to fall prey since the malicious activity appears to originate from someone they know and trust.
Steps iPhone Users Should Take Immediately
Sri Lanka CERT and cybersecurity experts recommend that iPhone users in Sri Lanka take the following steps without delay to reduce their risk of falling victim to this attack:
Update WhatsApp immediately: Ensure that your WhatsApp application is updated to the latest version available on the Apple App Store. Developers frequently release security patches to address known vulnerabilities, and running an outdated version significantly increases your exposure to such threats.
Update iOS: Keep your iPhone's operating system updated to the latest version. Apple regularly issues security updates that can help mitigate vulnerabilities exploited by zero-click attacks.
Enable Two-Step Verification: Activate WhatsApp's two-step verification feature by navigating to Settings, then Account, and then Two-Step Verification. This adds an additional layer of security that makes it harder for attackers to fully take over your account even if they gain initial access.
Monitor account activity: Regularly check your WhatsApp for any unusual activity, such as messages you did not send, unfamiliar linked devices, or unexpected logouts. If you notice anything suspicious, report it to CERT immediately.
Avoid connecting to unsecured networks: Public Wi-Fi networks can increase your vulnerability to various forms of cyberattacks. Use trusted networks and consider a reputable VPN service for added protection.
A Growing Cybersecurity Concern
This incident serves as a stark reminder of the evolving and increasingly sophisticated nature of cyber threats facing everyday users in Sri Lanka and around the world. As digital communication platforms become more deeply embedded in daily life, they also become more attractive targets for cybercriminals. Sri Lanka CERT's proactive advisory highlights the importance of maintaining strong cybersecurity hygiene and staying informed about emerging threats. Users are encouraged to follow CERT's official channels for the latest updates and guidance as this situation continues to develop.