A sophisticated new phishing campaign identified targeting job seekers with fraudulent Meta and WhatsApp employment opportunities.
The attack, which emerges amid a 12% rise in global phishing attempts since 2024, employs advanced social engineering tactics to harvest credentials and extort money from victims seeking career opportunities.
The phishing operation begins with attackers creating deceptive domains that closely mimic official Meta and WhatsApp career portals.
The fraudulent websites utilize Meta Quest branding and incorporate Facebook login options to create an air of legitimacy while harvesting user credentials.
“These attacks are getting more sophisticated – using convincing branding, login portals, and even pressure tactics like ‘equipment purchases’ to extract credentials and cash,” Eshed, Co-Founder and CEO at LayerX Security, said to Cyber Security News.
Technical analysis reveals the attackers deploy a multi-stage attack vector:
This campaign aligns with broader cybersecurity trends in 2025, where phishing attacks have evolved significantly.
Recent data indicates approximately 3.4 billion phishing emails are dispatched daily, with smishing attacks increasing by 250% compared to previous years.
This particular attack targets the increasing number of job seekers looking for remote work opportunities at major tech companies. By exploiting the Meta and WhatsApp brands, attackers tap into the significant trust these platforms maintain among users.
“The creators of this site went to great lengths to create a job application experience that would look legitimate even upon close inspection, including creating comprehensive application flows, possibly with the use of GenAI,” noted security researchers.
LayerX Security identified this threat through its browser-level protection system, which analyzes over 250 real-time parameters to detect phishing attempts before credentials can be compromised.
The system flagged suspicious elements in the URL structure and domain registration patterns that traditional security measures might miss.
“These are the kinds of threats that bypass traditional security layers. If your organization isn’t already thinking browser-first, let’s talk,” Eshed emphasized.
Security experts recommend several measures to protect against such attacks:
As phishing tactics evolve in sophistication through 2025, particularly with the integration of AI-generated content making attacks harder to detect, users must maintain heightened vigilance against unsolicited job opportunities regardless of how legitimate they may appear.
With vishing attacks up 28% and smishing incidents rising by 22% in recent quarters, cybersecurity experts predict continued targeting of job seekers as economic pressures make employment-related phishing particularly effective.
Malware Trends Report Based on 15000 SOC Teams Incidents, Q1 2025 out!-> Get Your Free Copy
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…