VYPR
researchPublished Aug 11, 2026· 1 source

Phishing Campaigns Exploit SSL/TLS Certificates to Impersonate Brands on WhatsApp and Instagram

Attackers are using legitimate SSL/TLS certificates and typosquatting to create convincing fake login pages on WhatsApp and Instagram, aiming to steal user credentials.

A new phishing campaign is actively exploiting the trust users place in SSL/TLS certificates to impersonate high-value brands across platforms like WhatsApp and Instagram. Attackers are registering domain names that closely mimic legitimate brands through subtle typosquatting techniques, such as character substitutions and orthographic variations. Once these lookalike domains are established, they are equipped with valid SSL/TLS certificates, enabling secure HTTPS connections.

This tactic allows malicious login pages to display the familiar padlock icon and HTTPS indicator, creating a false sense of security for unsuspecting users. The campaign's infrastructure, including phishing and interface-cloning sites, was recently activated, with certificates issued on August 10, 2026, indicating a fresh wave of social engineering. Researchers from Clandestine identified this activity, highlighting that the immediate risk stems not from a flaw in the certificate system itself, but from the misplacement of user trust.

On mobile devices, where full URLs can be obscured or truncated, the visual cues of a secure connection are particularly deceptive. Users may enter credentials on these fraudulent pages before scrutinizing the actual domain name, leading to account takeovers, financial fraud, and identity theft. The campaign leverages classic typosquatting patterns, making it difficult for users to distinguish between legitimate and fake sites at a glance.

The primary targets appear to be users of WhatsApp and Instagram, platforms that facilitate widespread communication and can be used to deliver urgent-seeming lures. Messages might claim account verification is needed, a payment is pending, or support is required, prompting users to click on a link. The cloned pages then solicit login details, one-time verification codes, or other sensitive personal information.

While the campaign is not yet attributed to a specific threat actor, and no victims have been confirmed, the certificate issuers involved include well-known authorities like Let's Encrypt, Google Trust Services, and Amazon. This is standard practice, as certificate issuance primarily validates domain control, not the legitimacy of the website's content or branding.

To combat this threat, users are advised to exercise extreme caution with unsolicited links received via chat applications, even if they appear to originate from known contacts. It is recommended to manually navigate to official websites or open applications directly rather than clicking on suspicious links. Users should also expand address bars to inspect full domain names before entering any credentials and treat unsolicited verification codes as highly sensitive.

Organizations can bolster defenses by monitoring for newly issued certificates associated with brand-like domains and by proactively warning customers about verified support channels. Implementing multi-step sign-in protections and regularly reviewing active sessions can further mitigate the risk of account compromise. The core lesson remains: an encrypted connection (HTTPS) signifies secure data transmission, not necessarily an authentic or trustworthy website.

Synthesized by Vypr AI