Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical ClamAV Vulnerabilities Let Attackers Trigger DoS
August 11, 2026
Phishing Attack Uses SSL/TLS Certificates to Target WhatsApp Users
August 11, 2026
OpenAI Daybreak Cyber Adds GPT-5.6 for Exploit Validation and Pentesting
August 11, 2026
Home/CyberSecurity News/Phishing Attack Uses SSL/TLS Certificates to Target WhatsApp Users
CyberSecurity News

Phishing Attack Uses SSL/TLS Certificates to Target WhatsApp Users

Key Takeaways A new phishing campaign is leveraging SSL/TLS certificates and typosquatting to target users of high-value brands, particularly WhatsApp and Instagram. Attackers create convincing fake...

Sarah simpson
Sarah simpson
August 11, 2026 4 Min Read
2 0

Key Takeaways

  • A new phishing campaign is leveraging SSL/TLS certificates and typosquatting to target users of high-value brands, particularly WhatsApp and Instagram.
  • Attackers create convincing fake websites with legitimate HTTPS encryption, tricking users into believing the sites are secure and authentic.
  • The primary risk stems from misplaced trust in the padlock icon and shortened URLs on mobile devices, leading to credential theft and account compromise.
  • No specific vulnerability in the certificate system is being exploited; rather, it is a social engineering attack exploiting user perception of security.

Sophisticated Phishing Campaign Exploits SSL/TLS to Target WhatsApp Users

A sophisticated phishing operation is actively targeting customers of prominent brands, particularly those using WhatsApp and Instagram, by employing legitimate web certificates and carefully chosen deceptive domain names. This campaign aims to make fraudulent web pages appear authentic at first glance, turning a common security indicator—the HTTPS padlock—into a tool for deception.

Table Of Content

  • Key Takeaways
  • Sophisticated Phishing Campaign Exploits SSL/TLS to Target WhatsApp Users
  • How Attackers Leverage SSL/TLS Certificates
  • WhatsApp Lures Can Turn Trust Into Theft
  • What You Should Do

The attackers establish fake websites using domain names that closely resemble legitimate services through typosquatting techniques. Victims are lured from WhatsApp messages to these fraudulent login pages, which mimic familiar platforms. On these deceptive sites, users are prompted to enter sensitive information such as passwords, verification codes, and other account details, which are then harvested by the attackers.

Researchers from Clandestine have identified and reported on the active phishing and interface-cloning infrastructure supporting this campaign. According to their findings, the SSL/TLS certificates for these malicious sites were issued on August 10, 2026, indicating that these supporting sites were recently prepared for a new wave of social engineering attacks. A detailed report by Clandestine indicated that the immediate threat is not a vulnerability within the certificate system itself, but rather the exploitation of user trust. Individuals often see the HTTPS prefix or a padlock icon, mistakenly assuming the page is legitimate, and proceed to enter credentials without thoroughly verifying the full web address. This oversight can lead to severe consequences, including account takeovers, financial fraud, and identity impersonation.

How Attackers Leverage SSL/TLS Certificates

The attackers register domains that closely imitate well-known brands by using subtle spelling variations, adding extra words, or substituting characters—a technique known as typosquatting. They then obtain valid SSL/TLS certificates from legitimate certificate authorities like Let’s Encrypt, Google Trust Services, and Amazon. These certificates enable the fake websites to load over encrypted HTTPS connections, displaying the familiar padlock icon in web browsers.

While HTTPS encryption ensures that the communication between a user’s browser and the website is secure from eavesdropping, it does not verify the authenticity or honesty of the website operator. This distinction is particularly critical on mobile devices, where browser interfaces often hide or truncate the full URL, making it difficult for users to spot the deceptive domain. A fraudulent page can thus display a seemingly reassuring lock icon while actively designed to steal user information. Similar tactics have been observed in job seeker WhatsApp phishing campaigns, where spoofed domains with HTTPS were used to lend credibility to fake recruitment offers.

As Clandestine said in a report shared with Cyber Security News (CSN), the campaign employs classic typosquatting patterns, including character substitution and various orthographic manipulations. The primary targets identified are WhatsApp and Instagram users, due to the platforms’ extensive reach for disseminating messages and alerts. While the campaign’s infrastructure has been detailed, current reporting does not attribute it to a specific threat group or confirm the number of victims.

The involvement of certificate issuers like Let’s Encrypt, Google Trust Services, and Amazon does not imply their complicity in the fraud. Certificate issuance is an automated process that validates control over a domain, not the integrity of its content or the brand identity suggested by its name. The following tweet from Clandestine illustrates the nature of these campaigns: pic.twitter.com/6nJv18JJnQ

WhatsApp Lures Can Turn Trust Into Theft

The effectiveness of this phishing campaign largely stems from its exploitation of urgency and familiarity. Victims receive WhatsApp messages claiming issues such as account verification requirements, pending payments, or urgent support actions. Clicking these links leads them to cloned pages that demand logins, one-time codes, or personal data. Compliance with these requests leaves users vulnerable to account compromise.

The indicators of compromise (IoCs) identified by researchers include several domains designed for typosquatting, such as:

  • whatsapp.elirex.net
  • whatsapp.primecore.online
  • whatsapp-handler.icaal.co.uk
  • whatsappclone-dc983:... (truncated)
  • api.whatsapp.dev.tadoo.app

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

What You Should Do

  • Verify Links Carefully: Avoid clicking unexpected account links sent via chat applications. Instead, open the official app directly or manually type the service’s known web address into your browser. This habit can defeat visual tricks used in recent typosquatting phishing cases.
  • Inspect Full URLs: Before entering any credentials, expand the address bar in your browser and thoroughly inspect the complete domain name. Do not rely solely on the brand name displayed or the presence of a padlock icon.
  • Treat Verification Codes as Sensitive: Never share unsolicited verification codes with anyone. Legitimate services will not ask for these codes in an unexpected manner.
  • Enable Multi-Factor Authentication (MFA): Activate multi-step sign-in protections on all your online accounts. This adds a crucial layer of security, making it significantly harder for attackers to access your accounts even if they steal your password.
  • Review Active Sessions: Regularly check your account settings for active sessions and log out of any unfamiliar or suspicious ones after any suspicious contact.
  • Change Passwords Immediately: If you suspect you have entered your login details on a questionable page, immediately change your password through the official service’s website or app.
  • Alert Your Contacts: Inform your contacts if you believe your account has been compromised, as attackers may use it to spread further phishing messages.
  • Organizations: Monitor for new SSL/TLS certificates issued for brand-like domains and proactively warn customers about verified support channels. Add reported malicious domains to monitoring and blocking workflows. Remember, a certificate confirms encryption, not authenticity.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitphishingSecurityThreat

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

OpenAI Daybreak Cyber Adds GPT-5.6 for Exploit Validation and Pentesting

Next Post

Critical ClamAV Vulnerabilities Let Attackers Trigger DoS

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Vulnerability Lets Attackers Bypass MFA in Windows 11 and Entra ID
August 10, 2026
Critical HP ThinPro TPM Flaw Exposes LUKS Disk Encryption Keys
August 10, 2026
Critical Windows WalletService Bug (CVE-2024-XXXX) Lets Attackers Escalate Privileges
August 10, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Emy Elsamnoudy
Emy Elsamnoudy
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us