{"id":10869,"date":"2026-02-23T10:04:00","date_gmt":"2026-02-23T10:04:00","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/02\/23\/threat-actors-allegedly-selling-whatsapp-crash-exploit-on-hacking-forums\/"},"modified":"2026-02-23T10:04:00","modified_gmt":"2026-02-23T10:04:00","slug":"threat-actors-allegedly-selling-whatsapp-crash-exploit-on-hacking-forums","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/02\/23\/threat-actors-allegedly-selling-whatsapp-crash-exploit-on-hacking-forums\/","title":{"rendered":"Threat Actors Allegedly Selling WhatsApp Crash Exploit on Hacking Forums"},"content":{"rendered":"<p>    Threat Actors Allegedly Selling WhatsApp Crash Exploit on Hacking Forums<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A recent discovery on underground hacking forums has raised alarms about a new exploit targeting the popular messaging application, WhatsApp.<\/p>\n<p>Threat intelligence platforms have identified a threat actor allegedly offering a script designed to crash the application across multiple operating systems.<\/p>\n<p>This development highlights the ongoing efforts of malicious actors to identify and exploit vulnerabilities in widely used communication platforms.<\/p>\n<p>The threat actor is asking for a relatively low price of $30 for this exploit, making it accessible to a wide range of potential buyers, including those with limited technical skills.<\/p>\n<p>According to information shared by threat intelligence source Dark Web Informer, a malicious script is currently being advertised for sale on <a href=\"https:\/\/cybersecuritynews.com\/26000-discussions-on-dark-web-forums\/\" target=\"_blank\" rel=\"noreferrer noopener\">a dark web hacking forum<\/a>.<\/p>\n<p>The advertisement claims that the script can cause significant disruptions to the normal functioning of <a href=\"https:\/\/cybersecuritynews.com\/whatsapp-device-fingerprinting\/\" target=\"_blank\" rel=\"noreferrer noopener\">WhatsApp on various devices<\/a>.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-cross-platform-disruption-claims\"><strong>Cross-Platform Disruption Claims<\/strong><\/h2>\n<p>The exploit reportedly targets both major mobile operating systems. The seller alleges that the script can cause the WhatsApp application to crash entirely on Android devices.<\/p>\n<p><span style=\"box-sizing: border-box; margin: 0px; padding: 0px;\">For<a href=\"https:\/\/cybersecuritynews.com\/whatsapp-0-day-vulnerability\/\" target=\"_blank\" rel=\"noopener\">\u00a0iOS users<\/a>, the exploit is claimed to not only cause the application to crash but also specifically freeze group chats, rendering that\u00a0<\/span>feature unusable.<\/p>\n<p>This <a href=\"https:\/\/cybersecuritynews.com\/python-based-pyrat-with-cross-platform-capabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">cross-platform capability increases<\/a> the exploit\u2019s potential impact, as it can affect a larger portion of WhatsApp\u2019s massive user base.<\/p>\n<p>Beyond simply crashing the application, the advertisement lists several other disruptive features included in the $30 package.<\/p>\n<p>The script allegedly includes capabilities for <a href=\"https:\/\/cybersecuritynews.com\/zoom-security-enhancements\/\" target=\"_blank\" rel=\"noreferrer noopener\">call and video call bombing<\/a>, which involves overwhelming a target user with a rapid succession of incoming calls, rendering their device virtually unusable during the attack.<\/p>\n<p>Additionally, the exploit is said to feature pair spam capabilities. However, the exact mechanism of this specific function was not fully detailed in the advertisement.<\/p>\n<p>The exploit requires minimal operational setup, significantly lowering the barrier for potential attackers, according to a <a href=\"https:\/\/x.com\/DarkWebInformer\/status\/2025625759541350728\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">post on X by threat intelligence source Dark Web Informer.<\/a><\/p>\n<p>The seller claims that the script can be executed via Termux, a terminal emulator and <a href=\"https:\/\/cybersecuritynews.com\/google-patched-linux-kernel-vulnerability-in-android\/\" target=\"_blank\" rel=\"noreferrer noopener\">Linux environment app for Android.<\/a><\/p>\n<p>This means the attack can be launched directly from a mobile device without the need for a Virtual Private Server or complex infrastructure.<\/p>\n<p>The attacker only <a href=\"https:\/\/cybersecuritynews.com\/virtual-numbers-for-paypal-verification\/\" target=\"_blank\" rel=\"noreferrer noopener\">needs a virtual phone number to run the script<\/a>, adding a layer of anonymity to the disruptive activity.<\/p>\n<p>While the exact technical details of the vulnerability being exploited remain unclear, the availability of such a tool on the dark web is a concerning development.<\/p>\n<p>Users are advised to ensure their WhatsApp applications are always updated to the latest version, as developers frequently release patches to address newly discovered security flaws and improve application stability.<\/p>\n<p>Security teams will continue to monitor these forums to analyze emerging threats and provide timely warnings to the user community.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/threat-actors-whatsapp-crash-exploit\/\">Threat Actors Allegedly Selling WhatsApp Crash Exploit on Hacking Forums<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/threat-actors-whatsapp-crash-exploit\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Threat Actors Allegedly Selling WhatsApp Crash Exploit on Hacking Forums A recent discovery on underground hacking forums has raised alarms about a new exploit targeting the popular messaging application, WhatsApp. Threat intelligence platforms have identified a threat actor allegedly offering a script designed to crash the application across multiple operating systems. This development highlights the [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,460],"tags":[130],"class_list":["post-10869","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-whatsapp","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/10869"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=10869"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/10869\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=10869"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=10869"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=10869"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}