{"id":18702,"date":"2022-04-07T05:10:21","date_gmt":"2022-04-07T13:10:21","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2022\/04\/07\/news-12435\/"},"modified":"2022-04-07T05:10:21","modified_gmt":"2022-04-07T13:10:21","slug":"news-12435","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2022\/04\/07\/news-12435\/","title":{"rendered":"Watch out for fake WhatsApp &#8220;New Incoming Voicemessage&#8221; emails"},"content":{"rendered":"<p><strong>Credit to Author: Jovi Umawing| Date: Thu, 07 Apr 2022 12:54:27 +0000<\/strong><\/p>\n<p><em>Thanks to the <a href=\"https:\/\/blog.malwarebytes.com\/category\/threat-intelligence\/\">Threat Intelligence<\/a> team for their help with this article.<\/em><\/p>\n<p>Security researchers from Armorblox, a cybersecurity company specializing in email-based threats, <a href=\"https:\/\/www.armorblox.com\/blog\/whatsapp-voicemail-phishing-attack\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">have encountered<\/a> a fake WhatsApp email with the subject &#8220;New Incoming Voicemessage.&#8221;<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"55520\" data-permalink=\"https:\/\/blog.malwarebytes.com\/social-engineering\/2022\/04\/watch-out-for-fake-whatsapp-new-incoming-voicemessage-emails\/attachment\/armorblox-whastsapp-phishing-email\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/armorblox-whastsapp-phishing-email.png\" data-orig-size=\"1942,1242\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"armorblox-whastsapp-phishing-email\" data-image-description=\"\" data-image-caption=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/armorblox-whastsapp-phishing-email-300x192.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/armorblox-whastsapp-phishing-email-600x384.png\" width=\"600\" height=\"384\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/armorblox-whastsapp-phishing-email-600x384.png\" alt=\"\" class=\"wp-image-55520\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/armorblox-whastsapp-phishing-email-600x384.png 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/armorblox-whastsapp-phishing-email-300x192.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/armorblox-whastsapp-phishing-email-1536x982.png 1536w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/armorblox-whastsapp-phishing-email.png 1942w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><figcaption>The spoofed WhatsApp voicemail notification email. (Source: <a href=\"https:\/\/www.armorblox.com\/blog\/whatsapp-voicemail-phishing-attack\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Armorblox<\/a>)<\/figcaption><\/figure>\n<\/div>\n<p>The sender is &#8220;Whatsapp Notifier,&#8221; a spoofed name, and an email address using a legitimate domain belonging to <a href=\"http:\/\/cbddmo.ru\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">a Russian road safety organization<\/a>, to sneak through mail filters.<\/p>\n<p>Recipients are encouraged to click a &#8220;Play&#8221; button and listen to their voicemail. That doesn&#8217;t happen, though\u2014clicking &#8220;Play&#8221; directs recipients to a page where Aromorblox found an obfuscated, malicious JavaScript that redirected users to another page. The second page included an exploit, triggered when users responded to an Allow\/Block prompt.<\/p>\n<p>Prompts like this are also used by <a href=\"https:\/\/blog.malwarebytes.com\/glossary\/malvertising\/\">malvertisers<\/a> when they want to push ads in front of users.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-medium\"><img decoding=\"async\" data-attachment-id=\"55550\" data-permalink=\"https:\/\/blog.malwarebytes.com\/social-engineering\/2022\/04\/watch-out-for-fake-whatsapp-new-incoming-voicemessage-emails\/attachment\/allow-block-notif\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/allow-block-notif.png\" data-orig-size=\"514,296\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"allow-block-notif\" data-image-description=\"\" data-image-caption=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/allow-block-notif-300x173.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/allow-block-notif.png\" loading=\"lazy\" width=\"300\" height=\"173\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/allow-block-notif-300x173.png\" alt=\"\" class=\"wp-image-55550\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/allow-block-notif-300x173.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/allow-block-notif.png 514w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><figcaption>A malvertisers&#8217; Allow\/Block prompt<\/figcaption><\/figure>\n<\/div>\n<p>Ads can include (but are not limited to) scam sites, portals for unwanted browser extensions (<a href=\"https:\/\/blog.malwarebytes.com\/glossary\/pup\/\">PUPs<\/a>), and even malware. The ads vary depending on a user&#8217;s device and location.<\/p>\n<p>When we clicked the &#8220;Allow&#8221; button during our own testing, we were signed up to receive notifications from <code>bingocaptchapoint.top<\/code>.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img decoding=\"async\" data-attachment-id=\"55551\" data-permalink=\"https:\/\/blog.malwarebytes.com\/social-engineering\/2022\/04\/watch-out-for-fake-whatsapp-new-incoming-voicemessage-emails\/attachment\/subbed\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/subbed.png\" data-orig-size=\"333,171\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"subbed\" data-image-description=\"\" data-image-caption=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/subbed-300x154.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/subbed.png\" loading=\"lazy\" width=\"333\" height=\"171\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/subbed.png\" alt=\"\" class=\"wp-image-55551\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/subbed.png 333w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/subbed-300x154.png 300w\" sizes=\"auto, (max-width: 333px) 100vw, 333px\" \/><figcaption>Malvertisers sign a browser up for notifications <\/figcaption><\/figure>\n<\/div>\n<p>The domain we had agreed to receive notifications from then used its priveleged position to redirect us to a page with a bogus offer.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img decoding=\"async\" data-attachment-id=\"55564\" data-permalink=\"https:\/\/blog.malwarebytes.com\/social-engineering\/2022\/04\/watch-out-for-fake-whatsapp-new-incoming-voicemessage-emails\/attachment\/fiddler-view-of-malvertising\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/fiddler-view-of-malvertising.png\" data-orig-size=\"560,493\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Malvertising seen through Fiddler\" data-image-description=\"\" data-image-caption=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/fiddler-view-of-malvertising-300x264.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/fiddler-view-of-malvertising.png\" loading=\"lazy\" width=\"560\" height=\"493\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/fiddler-view-of-malvertising.png\" alt=\"Malvertising seen through Fiddler\" class=\"wp-image-55564\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/fiddler-view-of-malvertising.png 560w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/fiddler-view-of-malvertising-300x264.png 300w\" sizes=\"auto, (max-width: 560px) 100vw, 560px\" \/><figcaption>Malvertising using a domain with permission to trigger browser notifications to redirect a user<\/figcaption><\/figure>\n<\/div>\n<p>Ten seconds after subscribing we hit our first ad: A Google Chrome &#8220;search contest&#8221;. And will you look at that?\u2014we won! <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img decoding=\"async\" data-attachment-id=\"55556\" data-permalink=\"https:\/\/blog.malwarebytes.com\/social-engineering\/2022\/04\/watch-out-for-fake-whatsapp-new-incoming-voicemessage-emails\/attachment\/chrome-search-contest-2022\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/chrome-search-contest-2022.png\" data-orig-size=\"900,596\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Fake Chrome search contest\" data-image-description=\"\" data-image-caption=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/chrome-search-contest-2022-300x199.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/chrome-search-contest-2022-600x397.png\" loading=\"lazy\" width=\"600\" height=\"397\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/chrome-search-contest-2022-600x397.png\" alt=\"Fake Chrome search contest\" class=\"wp-image-55556\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/chrome-search-contest-2022-600x397.png 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/chrome-search-contest-2022-300x199.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/chrome-search-contest-2022.png 900w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><figcaption>The malvertiser&#8217;s fake &#8220;Chrome search contest&#8221;<\/figcaption><\/figure>\n<\/div>\n<p>This is one of many WhatsApp voicemail message scams. Another variant, <a href=\"https:\/\/www.scam-detector.com\/article\/5-scary-whatsapp-scams-you-need-to-avoid-today\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">detailed by Scam Detector<\/a>, tricks Android users into downloading a payload called &#8220;Browser 6.5&#8221; which signs then up to receive text messages from premium rate phone numbers, for example.<\/p>\n<h2>What to do?<\/h2>\n<p>If you&#8217;re a WhatsApp user, remain vigilant and stay up to date with changes to WhatsApp&#8217;s services, so you know how they work. (For example, WhatsApp recently announced <a href=\"https:\/\/blog.whatsapp.com\/making-voice-messages-better\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">six changes<\/a> to its voice message service.)<\/p>\n<p>Check what you are approving before clicking &#8220;Allow&#8221; on browser prompts, and use a security tool that can <a href=\"https:\/\/www.malwarebytes.com\/browserguard\">block malicious sites and scripts<\/a>.<\/p>\n<p>and if you sign up for notifications from a site by accident you can remove it in Google Chrome by following these steps: Open <strong>Settings<\/strong>, click <strong>Privacy and Security<\/strong>, click <strong>Site Settings<\/strong>, click <strong>Notifications<\/strong>, scroll to <strong>Allowed to send notifications<\/strong>. Click the &#8220;three dots&#8221; icon next to the site you want to remove and click <strong>Remove<\/strong>.<\/p>\n<p>If you believe you have fallen victim to this scam\u2014or any other\u2014at work, report the incident to your IT or security team.<\/p>\n<p>Stay safe!<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/social-engineering\/2022\/04\/watch-out-for-fake-whatsapp-new-incoming-voicemessage-emails\/\">Watch out for fake WhatsApp &#8220;New Incoming Voicemessage&#8221; emails<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/social-engineering\/2022\/04\/watch-out-for-fake-whatsapp-new-incoming-voicemessage-emails\/\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Jovi Umawing| Date: Thu, 07 Apr 2022 12:54:27 +0000<\/strong><\/p>\n<p>Scammers are using the popularity of messaging service WhatsApp to trick users into signing up for malvertising<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/social-engineering\/2022\/04\/watch-out-for-fake-whatsapp-new-incoming-voicemessage-emails\/\">Watch out for fake WhatsApp &#8220;New Incoming Voicemessage&#8221; emails<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[25442,25615,25616,25617,10531,2130,251,25618,10510,10440],"class_list":["post-18702","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-armorblox","tag-fake-voicemail","tag-fake-voicemail-notification","tag-lauryn-cash","tag-malvertising","tag-pups","tag-russia","tag-scam-detector","tag-social-engineering","tag-whatsapp"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/18702","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=18702"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/18702\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=18702"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=18702"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=18702"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}