A new phishing campaign is using the popular messaging app WhatsApp to trick users. Specifically, the phishing emails exploit WhatsApp voice messages and attempt to spread information-stealing malware. The malicious emails have targeted at least 27,655 users.
Info-stealing malware is very popular among cybercriminals and is distributed in a variety of ways. Phishing emails are perhaps the most common distribution method.
See also: Amazon: Phishing email threatens to permanently block accounts

In most cases, this malware is used to steal credentials stored in browsers and applications. However, it also targets cryptocurrency wallets, SSH keys, or even files stored on the computer.
Phishing emails with alleged WhatsApp voice messages
The new phishing campaign that uses WhatsApp voice messages to scam users was discovered by researchers at Armorblox.
The emails appear as a notification from WhatsApp and inform the recipient that they have received a new private message. The email includes a built-in "Play" button and shows details about the duration and time the clip was created.
According to researchers, the sender, disguised as a "WhatsApp Notifier" service, uses an email address belonging to the Moscow Region Road Safety Center. Because this is a genuine and legitimate entity, the phishing emails are not flagged as dangerous and are not blocked by email security solutions.

Armorblox believes that the attackers somehow exploited the domain, and thus the organization is playing a role in this phishing campaign, without knowing it.
See also: Abuse of Calendly for phishing attacks
If the recipient clicks the "Play" button, they are redirected to a website that displays an allow/block message for the installation of a JS/Kryptic trojan.
How do criminals convince the user to click allow? A website appears stating that the user must click "Allow" to confirm that they are not a robot. In reality, however, this action will enroll the user in browser notifications that send in-browser ads for scams, adult sites, and malware.
Once the "allow" option is pressed, the browser will prompt the user to install the payload, which in this case is info-stealing malware.

WhatsApp Phishing Campaign: Protection
As we said above, the email managed to reach many inboxes, bypassing security solutions.
See also: WhatsApp update: You will hear voice messages while sending texts to others
However, there are indications that this is a scam:
- The email address has nothing to do with WhatsApp , and the same goes for the URL that asks victims to click "Allow" to confirm they are not a robot.
- Voice messages received on WhatsApp are automatically downloaded to the app, so there is no email notification of receipt of such a message.
- The phishing email does not have the WhatsApp logo
Therefore, whenever you receive a message, check it carefully and do not act hastily. Also, do not open attachments and links in emails that you are not expecting. More details on how to detect phishing emails can be found here.
Info-stealing malware is a growing threat, with new ones emerging every day. Earlier this month, a new malware called BlackGuardthat can steal data from a wide range of applications. It can steal all types of information related to Crypto wallets, VPNs, Messengers, FTP credentials, saved browser credentials , and more. However, it seems to be mainly focused on cryptocurrency assets.
Source: Bleeping Computer
