Fake WhatsApp/Instagram Sites Abuse HTTPS Padlock

eSecurity Planet · Medium sophistication
Last updated August 11, 2026

Researchers reported a phishing setup that clones WhatsApp and Instagram login pages and uses valid HTTPS (TLS) certificates to look legitimate. Victims are lured via WhatsApp messages about “verification,” “pending payments,” or “customer support,” then sent to typosquatted lookalike domains to steal passwords and one-time codes.

Key findings

  • Researchers observed newly activated phishing and interface-cloning infrastructure aimed at WhatsApp and Instagram users.
  • The suspicious domains obtained valid SSL/TLS certificates from mainstream CAs (Let’s Encrypt, Google Trust Services, Amazon), making the pages appear “secure” via HTTPS.
  • The domains use typosquatting (character substitutions, added words, spelling variations) to mimic brand domains.
  • Victims are lured by WhatsApp messages claiming account verification is needed, a payment is pending, or support action is required, then routed to a cloned login page to harvest credentials and one-time codes.
  • The core trick is user trust in the padlock/HTTPS indicator, encryption does not equal legitimacy, especially on mobile where full URLs may be truncated.

Who’s being targeted

  • Commonly targeted roles: All employees, Executives, Finance, Customer Support, Sales, Mobile device users.
  • Affected industries: Social media / messaging users, Consumer internet services, Enterprises whose employees use WhatsApp/Instagram on mobile devices.
  • Attack channels: whatsapp, website.
  • Impersonated: WhatsApp/Instagram support, WhatsApp/Instagram payments or customer service.

Awareness takeaways

  • Treat the padlock/HTTPS as “encrypted,” not “trusted”, always verify the full domain before entering credentials.
  • Avoid logging in from unexpected links in chats; open the official app/site directly instead.
  • Never share unsolicited verification codes (one-time codes); they can enable account takeover.
  • Be extra cautious on mobile where the full URL may be hidden; expand and inspect the entire address.

Red flags to watch for

  • Unexpected message urging verification/support action
  • Link goes to a lookalike (typosquatted) domain rather than the official domain/app
  • Site shows HTTPS/padlock but the domain name is slightly wrong (extra words, spelling variations)
  • Sense of urgency around a payment
  • Request for verification code (one-time code) outside the official app
  • Mobile browser shows only part of the address, hiding the typosquat
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get a WhatsApp message: “Your Instagram needs verification, tap here.” The site is HTTPS, padlock and all. Here’s the trick: they clone the real WhatsApp or Instagram login and even grab legit TLS certificates from Let’s Encrypt or Google Trust, so the padlock looks perfect while the domain is slightly wrong. They push urgency: “payment pending” or “support action required,” then ask for your password and a one-time code. On mobile, the browser hides most of the URL, so you just see the padlock and the brand name up front. Remember this: padlock means encrypted, not trusted. If a chat tells you to log in, don’t tap the link, open the official WhatsApp or Instagram app yourself and check there.

Similar attacks

Zero-Click Prompts Hijack AI Browsers via Email/X

Zero-Click Prompts Hijack AI Browsers via Email/X

Zenity demonstrated real-world attack chains where hidden instructions in emails or content on X can hijack AI “agentic browsers” (ChatGPT Atlas and the Claude Chrome extension). In the demos, the AI agent can be steered to perform actions in the user’s already logged-in sessions, sending phishing…

August 6, 2026
AI Browser Tricked into Spamming WhatsApp, Shopping

AI Browser Tricked into Spamming WhatsApp, Shopping

Researchers showed how a malicious web page could trick OpenAI’s Atlas AI-enabled browser into taking actions a user didn’t intend, like spamming WhatsApp contacts or modifying an Amazon account. The attacks used prompt-injection style instructions hidden in a seemingly legitimate “newsletter…

August 6, 2026
Fake ChatGPT Billing Emails Steal Card Details

Fake ChatGPT Billing Emails Steal Card Details

Check Point reports that scammers are now impersonating ChatGPT/OpenAI in phishing campaigns, reflecting how mainstream the service has become. One documented example used a fake “ChatGPT Plus payment failure” notice that sent victims to a fraudulent payment page designed to capture full credit…

July 28, 2026
Fake Voicemail Alert Steals Google Passwords

Fake Voicemail Alert Steals Google Passwords

A real phishing campaign is tricking employees with a “missed voicemail” message that claims they have a new audio message. Clicking “Play Audio” sends victims through multiple trusted-looking redirects and ends on a fake Google sign-in page that captures Google Workspace credentials, potentially…

August 12, 2026
Phished npm Maintainer Led to Debug/Chalk Hijack

Phished npm Maintainer Led to Debug/Chalk Hijack

Amazon says North Korea-linked actors compromised widely used npm packages (including debug and chalk) by tricking a trusted maintainer into signing in through a lookalike npm domain. After gaining that trusted access, the attackers published malicious updates that altered crypto wallet…

July 30, 2026
Fake ChatGPT Billing Emails Steal Card Details

Fake ChatGPT Billing Emails Steal Card Details

Check Point reports that OpenAI’s ChatGPT became a top-10 most impersonated brand in Q2 2026 phishing. One observed example used a fake “ChatGPT Plus payment failed” billing email to drive victims to a credit-card theft page. The report also notes other brand-impersonation scams using cloned stores…

July 24, 2026