This WhatsApp Link Can Hand Over Your Account in Seconds
ID: 5ac32d48-61a3-58c1-bd1c-03c78553a7d1
STIX ID: report--5ac32d48-61a3-58c1-bd1c-03c78553a7d1
Feed Name: TechRepublic Security
A sophisticated phishing campaign attributed to Iranian Revolutionary Guards intelligence is using a fake WhatsApp Web login hosted on DuckDNS to push live QR codes to victims; when scanned, the attacker’s browser session is authenticated, enabling full WhatsApp account takeover and, if granted, remote activation of camera, microphone and location for ongoing surveillance. The campaign targets individuals abroad involved in political, media, activist, or research work related to Iran and was documented by researcher Nariman Gharib with corroborating media coverage.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
