logo

WeChat Phishing Attacks a Growing Threat Outside China

ID: 5ff8127d-c0f0-51db-8374-30c25ea36185

STIX ID: report--5ff8127d-c0f0-51db-8374-30c25ea36185

Feed Name: KnowBe4 Blog

Threat Score
60/100

Date Published: 2025-12-18

Date Updated: 2026-04-28

Author: KnowBe4 Threat Lab

...
...

KnowBe4 Threat Labs observed a growing global phishing campaign that embeds WeChat “Add Contact” QR codes in templated bulk emails to move targets into WeChat for personalized social-engineering and payment fraud. The campaign leverages Python-based SMTP mass-mailer toolkits that rotate sender identities, use disposable/synthetic domains without authentication, Base64-encoded HTML bodies, and characteristic MIME/header fingerprints to evade secure email gateways; attackers then perform small test payments (e.g., refundable background-check fees) via WeChat Pay to establish trust and enable further extortion. The report includes indicators and mitigations (advanced email detection, NLP/NLU models, zero-trust email policies, and user awareness) to detect and reduce risk from these “quishing” attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.