A new phishing attack is using web certificates and chosen web addresses to target customers of high-value brands through WhatsApp. The activity is designed to make fraudulent pages look normal at a glance, turning a familiar security signal into part of the deception.
The campaign relies on fake sites with lookalike names. A message can steer a recipient from WhatsApp to a sign-in page resembling a service they know, where passwords, verification details, or other account information may be collected.
Clandestine researchers identified activated phishing and interface-cloning infrastructure aimed primarily at WhatsApp and Instagram.
The certificates were issued on August 10, 2026, suggesting the supporting sites were recently prepared for a new social-engineering wave.
Clandestine said in a report shared with Cyber Security News (CSN) that the immediate risk is not a flaw in the certificate system.
It is misplaced trust: people may see HTTPS or a padlock, assume the page is legitimate, and enter credentials before checking the full address. This can cause account takeovers, fraud, and impersonation.
The attackers appear to have registered domains that imitate popular names through spelling changes, added words, and character substitutions.
They then obtained SSL/TLS certificates from legitimate certificate authorities, allowing pages to load over encrypted HTTPS connections.
Encryption protects traffic to a site, but does not prove that the operator is genuine.
This distinction matters on mobile screens, where the full address can be hidden or shortened.
A fraudulent page can display a lock icon and still be designed to steal information. Similar job seeker WhatsApp phishing campaigns have used spoofed domains and HTTPS to make false recruitment offers appear credible.
The activity uses classic typosquatting patterns, including character substitution and orthographic variations.
The reported targeting centers on WhatsApp and Instagram, where messages and alerts can reach a large audience. Available reporting does not attribute the campaign to a specific group or confirm victims.
The certificate issuers named in the research are Let’s Encrypt, Google Trust Services, and Amazon. This does not mean they are involved in fraud.
Certificate issuance is automated: a certificate validates control of a domain, not the honesty of its content or the brand identity implied by its name.
The campaign’s strength is likely its use of urgency and familiarity. A WhatsApp message might claim that an account needs verification, a payment is pending, or a support action is required.
A cloned page can then ask for a login, a one-time code, or personal information, leaving victims exposed if they comply.
Users should avoid opening account links sent unexpectedly in chats, even when they appear to come from a known contact. Instead, open the official app or type the known service address manually.
That habit helps defeat the visual tricks described in recent typosquatting phishing cases, where a small change can produce a convincing domain.
Before entering credentials, people should expand the address bar and inspect the complete domain rather than relying on the brand name at the beginning.
They should treat unsolicited verification codes as sensitive and never share them. Organizations can monitor new certificates for brand-like domains and warn customers about verified support channels.
Account holders should enable available multi-step sign-in protections and review active sessions after suspicious contact.
If a login has been entered on a questionable page, changing the password through the official service, ending unfamiliar sessions, and alerting contacts can limit damage.
Instagram credential theft reporting shows why replica pages remain effective when they exploit a trusted message or account.
Security teams should add reported domains to monitoring and blocking workflows where appropriate, while treating the list as a point-in-time view of infrastructure that can change.
The wider lesson is simple: a certificate means a connection is encrypted, not that a website, message, or request is authentic.
Similar SSL-backed phishing page attacks have used the padlock symbol to encourage that mistaken assumption.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| Domain | whatsapp.elirex.net | Reported WhatsApp-themed typosquatting domain |
| Domain | whatsapp.primecore.online | Reported WhatsApp-themed typosquatting domain |
| Domain | whatsapp-handler.icaal.co.uk | Reported WhatsApp-themed typosquatting domain |
| Domain | whatsappclone-dc983:... | Truncated indicator as provided in the source material |
| Domain | api.whatsapp.dev.tadoo.app | Reported WhatsApp-themed typosquatting domain |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world
Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…
The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…
CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…
Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…
You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…
Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…