A new phishing campaign is making fake websites look trustworthy by giving them the same HTTPS security signal people usually associate with legitimate sites.
Security researchers at Clandestine said they identified newly activated phishing and interface-cloning infrastructure that appears designed to target customers of high-value brands, with a primary focus on WhatsApp and Instagram.
According to the researchers, SSL/TLS certificates for the suspicious domains were issued on Aug. 10 by legitimate certificate authorities, including Let’s Encrypt, Google Trust Services, and Amazon. The domains use typosquatting techniques such as character substitutions, added words, and spelling variations to imitate well-known brands.
Examples cited by Clandestine include addresses resembling WhatsApp-related services, suggesting the infrastructure was recently prepared for a new social-engineering campaign.
Encryption is not the same as legitimacy
The attack does not exploit a weakness in SSL/TLS certificates. Instead, it takes advantage of a common misconception: many users assume that a padlock icon or HTTPS connection automatically means a website is trustworthy.
Cyber Security News, citing Clandestine’s findings, reported that attackers can obtain valid certificates for domains they control, allowing phishing pages to load over encrypted connections even though the sites are fraudulent.
That distinction is especially important on mobile devices, where browsers often display only part of a web address. A fake page can appear secure at a glance while collecting passwords, verification codes, or other account information.
How the scam works
Researchers said victims may receive a WhatsApp message claiming that an account needs verification, a payment is pending, or customer support action is required. The message then directs the user to a cloned login page that closely resembles a legitimate service.
If a victim enters credentials or a one-time verification code, attackers can potentially gain access to the account and use it for fraud or impersonation.
Clandestine noted that the activity is consistent with newly provisioned infrastructure for a fresh credential-harvesting campaign.
The padlock is no longer a useful trust shortcut
The bigger problem is that attackers do not necessarily need to defeat HTTPS to make a phishing site convincing. They can use the same infrastructure that legitimate websites use and rely on users to interpret the resulting security indicators incorrectly.
That shifts some of the defensive burden from browser security indicators to domain awareness. On mobile devices especially, checking the complete address before entering credentials can be more useful than simply looking for HTTPS.
For consumers, the safest approach is to avoid unexpected account links sent through chats and instead open the official app directly. Users should never share unsolicited verification codes and should enable additional sign-in protections where available.
Read more: Browser Threats Expand Across Enterprise Networks examines how credential theft and other browser-based attacks are creating broader risks for organizations.





