Cyber Security News

New Phishing Attack Targeting Job Seekers via WhatsApp Offers

A sophisticated new phishing campaign identified targeting job seekers with fraudulent Meta and WhatsApp employment opportunities.

The attack, which emerges amid a 12% rise in global phishing attempts since 2024, employs advanced social engineering tactics to harvest credentials and extort money from victims seeking career opportunities.

Fake Meta and WhatsApp Job Sites

The phishing operation begins with attackers creating deceptive domains that closely mimic official Meta and WhatsApp career portals. 

The fraudulent websites utilize Meta Quest branding and incorporate Facebook login options to create an air of legitimacy while harvesting user credentials.

“These attacks are getting more sophisticated – using convincing branding, login portals, and even pressure tactics like ‘equipment purchases’ to extract credentials and cash,” Eshed, Co-Founder and CEO at LayerX Security, said to Cyber Security News.

Technical analysis reveals the attackers deploy a multi-stage attack vector:

  • Initial contact through WhatsApp messages or SMS (smishing).
  • Redirection to spoofed domains with HTTPS certificates from Let’s Encrypt.
  • Implementation of credential harvesting forms requesting full names, email addresses, and phone numbers.
  • Deployment of social engineering tactics to create urgency, including fabricated hiring timelines.

Rise of Job-Related Phishing in 2025

This campaign aligns with broader cybersecurity trends in 2025, where phishing attacks have evolved significantly. 

Recent data indicates approximately 3.4 billion phishing emails are dispatched daily, with smishing attacks increasing by 250% compared to previous years.

This particular attack targets the increasing number of job seekers looking for remote work opportunities at major tech companies. By exploiting the Meta and WhatsApp brands, attackers tap into the significant trust these platforms maintain among users.

“The creators of this site went to great lengths to create a job application experience that would look legitimate even upon close inspection, including creating comprehensive application flows, possibly with the use of GenAI,” noted security researchers.

LayerX Security identified this threat through its browser-level protection system, which analyzes over 250 real-time parameters to detect phishing attempts before credentials can be compromised. 

The system flagged suspicious elements in the URL structure and domain registration patterns that traditional security measures might miss.

“These are the kinds of threats that bypass traditional security layers. If your organization isn’t already thinking browser-first, let’s talk,” Eshed emphasized.

Security experts recommend several measures to protect against such attacks:

  • Enable two-factor authentication on all accounts.
  • Verify job offers through official channels by navigating directly to company websites.
  • Scrutinize URL structures before entering credentials.
  • Remain skeptical of job offers requesting payment for equipment or training.
  • Implement browser-level security controls for enterprise environments.

As phishing tactics evolve in sophistication through 2025, particularly with the integration of AI-generated content making attacks harder to detect, users must maintain heightened vigilance against unsolicited job opportunities regardless of how legitimate they may appear.

With vishing attacks up 28% and smishing incidents rising by 22% in recent quarters, cybersecurity experts predict continued targeting of job seekers as economic pressures make employment-related phishing particularly effective.

Malware Trends Report Based on 15000 SOC Teams Incidents, Q1 2025 out!-> Get Your Free Copy

Kaaviya

Kaaviya is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

5 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

5 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

6 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

8 hours ago