Skip to content

Information Security News

  • Home
  • Cyber Security
  • Cybercriminals
  • Data Leak
  • Google
    • Android
  • Information Security
  • Linux
  • Malware
  • Microsoft
    • Windows
  • Open Source Tool
  • Vulnerability
  • Technology

Information Security News

  • Home
  • Cyber Security
  • Cybercriminals
  • Data Leak
  • Google
    • Android
  • Information Security
  • Linux
  • Malware
  • Microsoft
    • Windows
  • Open Source Tool
  • Vulnerability
  • Technology
  • Data Leak / Vulnerability

Invisible Surveillance: Tool Exploits WhatsApp/Signal Network Latency to Track User Activity

by Nam Phong · December 16, 2025

A tool has been released into the public domain that enables covert monitoring of user activity on WhatsApp and Signal using nothing more than a phone number. This surveillance technique spans more than three billion accounts and can reconstruct a person’s daily routine with unsettling precision—pinpointing when they return home, periods of active smartphone use, sleep cycles, movement patterns, and extended offline intervals. A secondary effect is accelerated battery drain and increased mobile data consumption, all occurring without the device owner’s awareness.

The method exploits the way message delivery protocols function in popular messaging apps. It relies on low-level delivery acknowledgements and analyzes round-trip time (RTT)—the delay between sending a packet and receiving a response. These acknowledgements are issued automatically at the network layer, before any inspection of message content, allowing an external party to obtain measurable responses regardless of whether an actual conversation exists.

In practice, anyone can send so-called “pings” to a victim’s device. The app responds instantly, but the latency varies markedly depending on the phone’s state, the type of network connection, and signal conditions. Wi-Fi versus cellular access, an active screen versus standby mode—all produce distinct timing profiles that become easy to distinguish through frequent sampling.

This vulnerability was first comprehensively described by researchers from the University of Vienna and SBA Research in an academic paper published last year. The authors demonstrated that such hidden probes can be sent at very high frequencies—down to fractions of a second—without triggering notifications, pop-ups, or any visible traces in the app interface, even if the two parties have never communicated.

Those theoretical findings have now taken on a practical form. A researcher known as gommzystudio has published a working proof of concept on GitHub, illustrating just how easily sensitive information about phone usage can be extracted. The demonstration shows how a single phone number can reveal whether a device is active, idle, asleep, or completely offline, along with additional behavioral signals.

One particularly effective technique involves sending reactions to messages that do not exist. These requests never appear on the recipient’s device, yet they still trigger automatic delivery acknowledgements. The application first confirms receipt of the network packet and only afterward checks whether the referenced message exists, leaving the surveillance chain entirely invisible.

Experiments indicate that such probes can be executed at intervals of roughly 50 milliseconds without leaving any trace in the user interface. Meanwhile, the smartphone consumes significantly more power and transmits far more data. Detecting the activity is possible only by physically connecting the device to a computer and analyzing internal logs.

Interpreting these latency patterns unlocks extensive monitoring capabilities. Very low RTT values typically correspond to active phone use with the screen on and a Wi-Fi connection. Slightly slower responses suggest activity over cellular data. Higher delays are characteristic of standby mode on Wi-Fi, while very large delays point to sleep mode on cellular networks or poor reception. A complete lack of response indicates airplane mode or a powered-off device, and sharp fluctuations in latency betray physical movement.

Accumulating such measurements over time allows the construction of a detailed behavioral profile. Stable Wi-Fi patterns usually coincide with being at home, prolonged inactivity aligns with sleep, and distinctive cellular signatures reveal travel or прогулки outside.

The repository quickly attracted community attention, amassing hundreds of stars and dozens of forks in a short period. Although the author emphasizes the research and educational nature of the project, the tool is freely available to anyone, making real-world abuse a tangible concern.

The impact on device autonomy deserves special attention. Based on the original academic study, an attacker can nearly drain a battery within hours without any access to the account or the device itself. Under normal conditions, an idle smartphone loses less than 1% of charge per hour. During WhatsApp tests, however, an iPhone 13 Pro lost around 14% in the same period, an iPhone 11 about 18%, and a Samsung Galaxy S23 roughly 15%.

Signal proved more resilient due to built-in rate limiting on acknowledgements. Under identical conditions, battery drain was limited to about 1% per hour, as excessive requests were blocked. WhatsApp lacked such constraints at the time of testing, making the attack significantly more effective.

Mobile data usage also rises sharply, and bandwidth-sensitive applications—such as video calls—suffer noticeable degradation. Researchers further showed that response timing can be used to roughly infer a user’s geographic region, for example distinguishing Germany from the UAE. Employing multiple probing points from different countries could potentially refine location estimates even further.

Latency instability can reveal not only movement but also the type of device and operating system, as different models and platforms handle network packets differently. In effect, a single phone number becomes a gateway to multi-layered profiling.

To mitigate risk, users are advised to enable WhatsApp’s option to block messages from unknown accounts via advanced privacy settings. This may limit the volume of hidden probes from unfamiliar numbers, although the company does not disclose exact thresholds, leaving the attack vector partially open. Disabling read receipts reduces metadata leakage in normal chats but does not address the specific loophole involving reactions.

Signal offers more granular privacy controls, including the ability to disable delivery receipts and typing indicators. More broadly, researchers recommend disabling “last seen,” “online,” and similar activity markers across all messaging platforms whenever possible. Complete protection against metadata leakage remains one of the most challenging problems in information security.

As of December 2025, the vulnerability remains exploitable in both WhatsApp and Signal.

Related coverage

  • Secret Tate War Room Courses Exposed
  • GitSpawn Exposes AI Coding Agents
  • OpenAI Classifies Astra as Critical Threat
  • Over 36,000 Exposed Plex Servers Remain Unpatched
  • Massive Data Leak Exposes Vietnam Aviation Records

Support Our Threat Intelligence

If you find our technology report and cybersecurity news helpful, consider supporting our work.

Buy Me a Coffee Logo Buy Me a Coffee PayPal
Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Tags: Battery DraincybersecurityMetadata LeakNetwork LatencyprivacyProof of ConceptRTTSignalSurveillanceWhatsApp

Follow:

  • Next story Deep Leak: APT35 Hackers’ Payroll, Kashef Surveillance System, and 2004 Nuclear Spy Document Exposed
  • Previous story Apple Emergency Patch: Two WebKit Zero-Days Actively Exploited in Targeted iOS Attacks

  • Recent Posts
  • Popular Posts
  • Tags
  • Plex Media Server security update warning with thousands of exposed vulnerable instances online

    Vulnerability

    Over 36,000 Exposed Plex Servers Remain Unpatched

    September 11, 2026

  • Gigabud Vwork Android work profile cloning a fake banking app to evade fraud detection

    Malware

    Gigabud Abuses Android Work Profiles to Hide Bank Fraud

    September 11, 2026

  • Vietnam Elasticsearch cluster data leak showing exposed passenger records and flight information

    Data Leak

    Massive Data Leak Exposes Vietnam Aviation Records

    September 11, 2026

  • Passkey phishing attack flow and Microsoft identity cloud compromise

    Cybercriminals

    Passkey Phishing Attacks Compromise Microsoft Identity Cloud

    September 11, 2026

  • Cheap Wi-Fi repeater backdoor and hidden root access flaw hardware analysis

    Malware

    A 3-Pound Wi-Fi Repeater Backdoor Threatens Network Security

    September 10, 2026

  • WeChat zero-click worm exploiting WeChat VoIP memory corruption

    Vulnerability

    WeChat Zero-Click Worm Exposed in New Security Advisory

    September 9, 2026

  • OpenSUSE Leap 15.4 Beta releases, Linux distributions

    Linux

    OpenSUSE Leap 15.4 Beta releases, Linux distributions

    May 30, 2020

  • Ubuntu 16.04.6 LTS released: fix security vulnerabilities

    Linux

    Ubuntu 16.04.6 LTS released: fix security vulnerabilities

    March 1, 2019

  • GhostBSD 23.10.1 released, FreeBSD distribution

    Linux

    GhostBSD 23.10.1 released, FreeBSD distribution

    May 1, 2020

  • Solus 4.4 Fortitude releases, Linux distribution

    Linux

    Solus 4.4 Fortitude releases, Linux distribution

    January 26, 2020

  • AI AI security Android Apple APT BOTNET CISA cloud security Critical Infrastructure cryptocurrency cyberattack cybercrime Cyber Espionage cybersecurity Cybersecurity 2026 data breach DLL Sideloading Github google hacking Infosec InfoSec 2026 Infostealer Linux Linux Kernel malware Microsoft network security open source phishing privacy privilege escalation Prompt Injection ransomware RCE remote code execution security Social Engineering supply chain attack Tech News 2026 threat intelligence vulnerability windows Windows 11 zero-day
  • Home
  • About Us
  • Contact Us
  • DMCA NOTICE
  • Privacy Policy

Information Security News © 2026. All Rights Reserved.

Powered by  - Designed with Hueman Pro