A new phishing attack is leveraging web certificates and chosen URLs to target high-value brand customers via WhatsApp This article explores new phishing interface. . The scheme aims to make fraudulent pages appear legitimate by mimicking familiar security indicators, turning a common safeguard into part of the deception.

The campaign uses fake sites with similar names to trick recipients into navigating to sign-in pages that resemble service options they recognize. Researchers discovered activated infrastructure specifically targeting WhatsApp and Instagram, designed to lead users from their messaging app directly to interface-cloned login pages where sensitive information like passwords or verification details can be harvested. Users may see HTTPS or padlock indicators but still enter credentials without verifying the full address, leading to account takeovers, fraud, and impersonation.

Threat intelligence alert: New campaigns detected We've detected new phishing and interface-cloning campaigns leveraging SSL/TLS certificates with classic typosquatting patterns (character substitutions and orthographic variations) targeting... pic.twitter.com/6njv18jjnq The activity employs typical typosquatting tactics, including character substitution and spelling variations. Instead of opening the official app or manually typing in the known service address, this habit helps counteract recent typosquatting phishing scenarios where minor changes can create convincing domain names. If an unauthorized login has been made on a questionable page or through a replica account, changing the password via official channels, ending unfamiliar sessions, and alerting contacts can minimize potential damage.