CyberHappenings logo

Track cybersecurity events as they unfold. Sourced timelines. Filter, sort, and browse. Fast, privacy‑respecting. No invasive ads, no tracking.

Global WhatsApp Hijacking Campaign Exploits Session Hijacking and Account Takeover

First reported
Last updated
1 unique sources, 1 articles

Summary

Hide ▲

A widespread WhatsApp hacking campaign, dubbed HackOnChat, is targeting users globally through deceptive authentication portals and impersonation pages. The campaign leverages social engineering tactics to hijack active WhatsApp Web sessions and take over accounts. Attackers use fake security alerts, WhatsApp Web lookalike portals, and spoofed group-invite messages to trick users into compromising their accounts. The campaign has seen a surge in activity across the Middle East and Asia, with thousands of malicious URLs deployed rapidly through inexpensive top-level domains and modern website-building platforms. Once control is gained, attackers exploit the compromised accounts to target the victim's contacts, requesting money or sensitive information. They also sift through messages, media, and documents for personal, financial, or private data, which can be used for fraud, impersonation, or extortion. The compromised accounts are often used to send phishing messages, spreading the scam further.

Timeline

  1. 20.11.2025 13:30 1 articles · 23h ago

    HackOnChat Campaign Exploits WhatsApp Web for Global Account Hijacking

    A rapidly expanding WhatsApp hacking campaign, dubbed HackOnChat, is targeting users worldwide through deceptive authentication portals and impersonation pages. The campaign uses social engineering tactics to hijack active WhatsApp Web sessions and take over accounts. Attackers use fake security alerts, WhatsApp Web lookalike portals, and spoofed group-invite messages to trick users. The campaign has seen a surge in activity across the Middle East and Asia, with thousands of malicious URLs deployed rapidly through inexpensive top-level domains and modern website-building platforms.

    Show sources

Information Snippets