Suspected Phishing Sites Use Valid TLS Certificates to Mimic WhatsApp and Instagram

Researchers found suspected phishing sites impersonating WhatsApp and Instagram, showing why valid TLS certificates do not establish website legitimacy.

Aug 11, 2026
2 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

A new phishing campaign is making fake websites look trustworthy by giving them the same HTTPS security signal people usually associate with legitimate sites.

Security researchers at Clandestine said they identified newly activated phishing and interface-cloning infrastructure that appears designed to target customers of high-value brands, with a primary focus on WhatsApp and Instagram.

According to the researchers, SSL/TLS certificates for the suspicious domains were issued on Aug. 10 by legitimate certificate authorities, including Let’s Encrypt, Google Trust Services, and Amazon. The domains use typosquatting techniques such as character substitutions, added words, and spelling variations to imitate well-known brands.

Examples cited by Clandestine include addresses resembling WhatsApp-related services, suggesting the infrastructure was recently prepared for a new social-engineering campaign.

Encryption is not the same as legitimacy

The attack does not exploit a weakness in SSL/TLS certificates. Instead, it takes advantage of a common misconception: many users assume that a padlock icon or HTTPS connection automatically means a website is trustworthy.

Cyber Security News, citing Clandestine’s findings, reported that attackers can obtain valid certificates for domains they control, allowing phishing pages to load over encrypted connections even though the sites are fraudulent.

That distinction is especially important on mobile devices, where browsers often display only part of a web address. A fake page can appear secure at a glance while collecting passwords, verification codes, or other account information.

How the scam works

Researchers said victims may receive a WhatsApp message claiming that an account needs verification, a payment is pending, or customer support action is required. The message then directs the user to a cloned login page that closely resembles a legitimate service.

If a victim enters credentials or a one-time verification code, attackers can potentially gain access to the account and use it for fraud or impersonation.

Advertisement

Clandestine noted that the activity is consistent with newly provisioned infrastructure for a fresh credential-harvesting campaign.

The padlock is no longer a useful trust shortcut

The bigger problem is that attackers do not necessarily need to defeat HTTPS to make a phishing site convincing. They can use the same infrastructure that legitimate websites use and rely on users to interpret the resulting security indicators incorrectly.

That shifts some of the defensive burden from browser security indicators to domain awareness. On mobile devices especially, checking the complete address before entering credentials can be more useful than simply looking for HTTPS.

For consumers, the safest approach is to avoid unexpected account links sent through chats and instead open the official app directly. Users should never share unsolicited verification codes and should enable additional sign-in protections where available.

Read more: Browser Threats Expand Across Enterprise Networks examines how credential theft and other browser-based attacks are creating broader risks for organizations.

AA

Aminu Abdullahi is an experienced B2B technology and finance writer. He has written for various publications, including TechRepublic, eWEEK, Enterprise Networking Planet, eSecurity Planet, CIO Insight, Enterprise Storage Forum, IT Business Edge, Webopedia, Software Pundit, Geekflare and more.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.