Starting with version 2.40, Elcomsoft Extractor for WhatsApp supports physical and cloud acquisition of WhatsApp Business. The physical extraction method requires root access, while cloud acquisition requires authenticating into the user’s Google Drive account with proper authentication credential. In addition, a verification code received from WhatsApp as an SMS must be provided to decrypt the backup downloaded from Google Drive. In this guide, we’ll describe all the steps required to perform physical and cloud acquisition of WhatsApp Business.
Exclusively available to Android users, WhatsApp Business is an app offering a number of features aimed at small business owners. The free Android app allows businesses interact with their customers by using a number of automation tools to quickly find and respond to messages. With more than 10 million installations from to Google Play Store, WhatsApp Business has definitely gained traction with its customers.
It is important to note that WhatsApp Business is a separate app, and can run alongside with the regular WhatsApp app. However, unless the user has a dual-SIM phone and configures the two WhatsApp apps to use different phone numbers, only one of the apps can be active. If the user has a phone with a single SIM card, activating WhatsApp Business on that phone number will automatically deactivate the regular app, and vice versa.
WhatsApp is renowned for its security, and this tradition continues with the Business app. Compared to the ‘normal’ WhatsApp, the Business app has a different protection scheme that rules out physical acquisition from Android devices without root access. For this reason, Elcomsoft Extractor for WhatsApp must utilize root access in order to extract WhatsApp Business working database. As a result, a rooted Android phone is the required pre-requisite for physical extraction.
In order to extract information from a rooted device, perform the following steps.
In the majority of cases you’re likely to deal with Android phones that don’t have root access installed. Unless it’s an old handset with a known vulnerability, or it has its bootloader unlocked, rooting the phone may be difficult or unfeasible. For these situations, we developed a solution allowing you to extract WhatsApp Business data from a Google Drive backup. Quite obviously, you’ll need to authenticate into the user’s Google Account in order to download the backup. However, that’s not the end of it.
WhatsApp and WhatsApp Business encrypt their Google Drive backups (everything except media, which is available in plain form) with a key that is impossible to obtain from the device without root access. The encryption key is also held on WhatsApp servers, and is normally used when the user restores their cloud backup on a new device. Notably, Google Drive backups contain somewhat less information compared to what is available through physical extraction.
Elcomsoft Extractor for WhatsApp can register as a new WhatsApp Business client and obtain the encryption key from the server. In order to register as a WhatsApp Business client, the tool requests a one-time code received as an SMS from WhatsApp; you will be required to enter that code into Elcomsoft Extractor for WhatsApp to confirm registration.
Below are the steps to perform cloud acquisition of WhatsApp Business.
Elcomsoft Explorer for WhatsApp is a tool to download, decrypt and display WhatsApp communication histories. The tool automatically acquires WhatsApp databases from one or multiple sources, processes information and displays contacts, messages, call history and pictures sent and received. The built-in viewer offers convenient searching and filtering, and allows viewing multiple WhatsApp databases extracted from various sources.
Elcomsoft Explorer for WhatsApp official web page & downloads »