New Phishing Attack Leverage SSL/TLS Certificates to Target High-value Brands Customers Via Whatsapp

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

A phishing operation is using web certificates and chosen web addresses to target customers of high-value brands through WhatsApp.

The activity is designed to make fraudulent pages look normal at a glance, turning a familiar security signal into part of the deception.

The campaign relies on fake sites with lookalike names. A message can steer a recipient from WhatsApp to a sign-in page resembling a service they know, where passwords, verification details, or other account information may be collected.

Clandestine researchers identified activated phishing and interface-cloning infrastructure aimed primarily at WhatsApp and Instagram.

The certificates were issued on August 10, 2026, suggesting the supporting sites were recently prepared for a new social-engineering wave.

Clandestine said in a report shared with Cyber Security News (CSN) that the immediate risk is not a flaw in the certificate system.

It is misplaced trust: people may see HTTPS or a padlock, assume the page is legitimate, and enter credentials before checking the full address. This can cause account takeovers, fraud, and impersonation.

New Phishing Attack leverage SSL/TLS certificates

The attackers appear to have registered domains that imitate popular names through spelling changes, added words, and character substitutions.

They then obtained SSL/TLS certificates from legitimate certificate authorities, allowing pages to load over encrypted HTTPS connections.

Encryption protects traffic to a site, but does not prove that the operator is genuine.

This distinction matters on mobile screens, where the full address can be hidden or shortened.

A fraudulent page can display a lock icon and still be designed to steal information. Similar job seeker WhatsApp phishing campaigns have used spoofed domains and HTTPS to make false recruitment offers appear credible.

The reported targeting centers on WhatsApp and Instagram, where messages and alerts can reach a large audience. Available reporting does not attribute the campaign to a specific group or confirm victims.

The certificate issuers named in the research are Let’s Encrypt, Google Trust Services, and Amazon. This does not mean they are involved in fraud.

Certificate issuance is automated: a certificate validates control of a domain, not the honesty of its content or the brand identity implied by its name.

WhatsApp Lures Can Turn Trust Into Theft

The campaign’s strength is likely its use of urgency and familiarity. A WhatsApp message might claim that an account needs verification, a payment is pending, or a support action is required.

A cloned page can then ask for a login, a one-time code, or personal information, leaving victims exposed if they comply.

Users should avoid opening account links sent unexpectedly in chats, even when they appear to come from a known contact. Instead, open the official app or type the known service address manually.

That habit helps defeat the visual tricks described in recent typosquatting phishing cases, where a small change can produce a convincing domain.

Before entering credentials, people should expand the address bar and inspect the complete domain rather than relying on the brand name at the beginning.

They should treat unsolicited verification codes as sensitive and never share them. Organizations can monitor new certificates for brand-like domains and warn customers about verified support channels.

Account holders should enable available multi-step sign-in protections and review active sessions after suspicious contact.

If a login has been entered on a questionable page, changing the password through the official service, ending unfamiliar sessions, and alerting contacts can limit damage. 

Instagram credential theft reporting shows why replica pages remain effective when they exploit a trusted message or account.

Security teams should add reported domains to monitoring and blocking workflows where appropriate, while treating the list as a point-in-time view of infrastructure that can change.

The wider lesson is simple: a certificate means a connection is encrypted, not that a website, message, or request is authentic.

Similar SSL-backed phishing page attacks have used the padlock symbol to encourage that mistaken assumption.

Indicators of compromise (IoCs):-

Type Indicator Description
Domain whatsapp.elirex.net Reported WhatsApp-themed typosquatting domain
Domain whatsapp.primecore.online Reported WhatsApp-themed typosquatting domain
Domain whatsapp-handler.icaal.co.uk Reported WhatsApp-themed typosquatting domain
Domain whatsappclone-dc983:... Truncated indicator as provided in the source material
Domain api.whatsapp.dev.tadoo.app Reported WhatsApp-themed typosquatting domain

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world