WhatsApp Web is a tool tracked across 18 threat clusters and 28 intelligence report mentions on ThreatCluster. First observed November 12, 2025; most recent activity July 24, 2026.
In March 2026, the WhatsApp accounts of a federal MP and three staffers were compromised in a phishing attack believed to be orchestrated by a foreign state actor, likely Russia. The attack involved hackers requesting…
The Securities and Exchange Board of India (Sebi) has issued a warning regarding a growing cyber fraud known as the 'Boss Scam', where scammers impersonate CEOs and senior executives to trick finance employees into…
A critical vulnerability in the Adobe Acrobat Chrome extension, tracked as CVE-2026-48294 and named HermeticReader, allows attackers to access WhatsApp Web data without authentication. The flaw affects approximately 329…
In June 2026, a malware campaign was identified that spreads malicious VBScript files through WhatsApp direct messages. The campaign primarily targets users of WhatsApp Desktop and WhatsApp Web, with the highest number…
The Indian government has ordered Meta to stop the rollout of WhatsApp usernames due to security concerns. This decision follows a warning from CERT-In about a dangerous malware attack targeting WhatsApp Web and Desktop…
Cybercriminals are executing a new WhatsApp impersonation scam aimed at business leaders, including CEOs, CFOs, and accountants of large corporations in Hyderabad. The attackers send phishing links to official email…
Threat actors are exploiting WhatsApp's device-linking feature to hijack accounts through a campaign named GhostPairing. This attack method does not require authentication, as victims are deceived into linking the…
Hackers have gained full access to WhatsApp accounts by using social engineering techniques to target phone numbers, bypassing the need for passwords or technical exploits. Additionally, a separate incident involved the…
The Astaroth banking trojan has resurfaced, now spreading through WhatsApp in Brazil under the name 'Boto-Cor-de-Rosa' or 'Pink Dolphin.' This campaign utilizes worm-like tactics to target users and steal financial…
The Astaroth banking malware has resurfaced, utilizing WhatsApp as an automated infection vector specifically targeting Brazilian users. This new campaign is referred to as 'Boto Cor-de-Rosa' and has been identified by…