CTM360 Exposes a Global WhatsApp Hijacking Campaign: HackOnChat
These articles are AI-generated summaries. Please check the original sources for full details.
CTM360 Exposes a Global WhatsApp Hijacking Campaign: HackOnChat
CTM360 has uncovered a worldwide WhatsApp account-hijacking campaign using deceptive authentication portals. The operation, named HackOnChat, leveraged session hijacking and social engineering to compromise thousands of accounts.
Why This Matters
WhatsApp’s security relies on end-to-end encryption and user verification, but this campaign exploits human trust in familiar interfaces. Attackers bypass technical safeguards by tricking users into revealing authentication keys or hijacking active sessions. The scale of the attack—hundreds of incidents across the Middle East and Asia—highlights how social engineering remains a low-cost, high-impact vector, often outpacing technical defenses.
Key Insights
- “HackOnChat campaign, 2025”: CTM360 identified thousands of malicious URLs hosted on cheap domains, enabling rapid deployment.
- “Session Hijacking and Account Takeover”: Attackers use WhatsApp Web’s linked-device feature and spoofed security alerts to gain control.
- “Multilingual phishing infrastructure”: Campaigns adapted interfaces with country codes and languages to target global users.
Practical Applications
- Use Case: Enterprises using WhatsApp for customer support risk data breaches via compromised accounts.
- Pitfall: Relying solely on user authentication without multi-factor verification leaves accounts vulnerable to spoofed alerts.
References:
- https://thehackernews.com/2025/11/ctm360-exposes-global-whatsapp.html
- https://www.ctm360.com/reports/hackonchat-unmasking-the-whatsapp-hacking-scam
Continue reading
Next article
From 20.04 to 24.04 LTS: Safe Ubuntu Upgrade on DigitalOcean
Related Content
Global Smishing Campaign Linked to 194,000 Malicious Domains and Over $1 Billion in Fraud
A China-linked cybercriminal group, Smishing Triad, has used 194,000 malicious domains since 2024 to execute a global phishing operation, generating over $1 billion in fraud through smishing attacks targeting financial and government services.
X Urges Users to Re-Enroll Security Keys by November 10 to Prevent Lockouts
Social media platform X requires users with hardware 2FA keys to re-enroll by November 10, 2025, to avoid account lockouts during its domain transition from twitter.com to x.com.
Samsung Zero-Day Flaw Exploited to Deploy LANDFALL Android Spyware in Middle East
A critical Samsung Galaxy vulnerability (CVE-2025-21042) was exploited as a zero-day to deploy the LANDFALL spyware via WhatsApp images, targeting users in the Middle East before a patch in April 2025.