Experts at Kaspersky Lab have uncovered a modification of the popular WhatsApp messenger that contains previously unknown malicious software - an Android spyware Trojan identified as Trojan-Spy.AndroidOS.Agent.afq. According to the company's press release, this modification has been circulating in Telegram channels in Arabic and Azerbaijani languages for some time now.

Between October 5th and 31st, the company's security solutions thwarted over 340,000 attacks utilizing this malicious software across more than a hundred countries worldwide. The highest number of incidents was recorded in Azerbaijan, Saudi Arabia, Yemen, Turkey, and Egypt. Russian users have also reported attempted infections.

This new Trojan program has the capability to steal data from infected smartphones, including contact lists, account login credentials, and documents. It can also initiate audio recording from the device's microphone upon command. The spy module becomes active when the device is powered on or placed on a charger.

The primary source of infected files is Telegram channels, primarily in Arabic and Azerbaijani languages, with the total number of subscribers in the most popular channels reaching nearly two million users.

Kaspersky Lab has promptly notified Telegram about the presence of malicious software in the identified channels. Nevertheless, these malicious modifications are also being distributed through various websites where messenger mods can be downloaded.