TURNS out WhatsApp voice notes aren't as safe as you thought.
According to researchers, crooks are using a new phishing campaign that impersonates the popular feature to part you from your cash.
The scam is packaged in an email in which the attacker impersonates WhatsApp, experts at cybersecurity firm Armorblox wrote Wednesday.
It tells you that you have received a new private voicemail and to tap on a play button in the email to hear it.
Following those instructions will land you on a webpage that installs malware onto your device.
That dodgy download hunts down and hoovers up data on your phone or PC, potentially exposing you to credential theft.
Read more about WhatsApp
WhatsApp plots HUGE update that will totally change how you use the app
The WhatsApp text you need to delete as soon as you get it
It's possible that attackers could then use usernames and passwords stolen using the software to access your online bank account.
"The socially engineered email was titled 'New Incoming Voicemessage' and included a header in the email body reiterating the email title," Armorblox wrote.
"The email body spoofed a secure message from WhatsApp and suggested that the victim had received a new private voicemail."
Apparently, the attack has reached more than 28,000 inboxes already.
Most read in News Tech
Charlotte Dawson named and shamed on Instagram ‘naughty list’ over her posts
Bus-sized asteroid spotted DAYS before it passes closer to Earth than the Moon
You're using Apple iPhone app completely wrong – and it's wasting your time
Thousands of Brits unable to access emails on Yahoo Mail after server fails
It has largely targeted organisations across healthcare, education, and retail.
The attacks are said to be sophisticated enough that they easily bypass Microsoft and Google email security filters.
It's unclear who is behind the attacks, but they appear to run their operation through Russian websites, researchers said.
This does not confirm that the hackers are Russian, however, as they could have taken control of the domain from another country.
It's one of a rising number of phishing campaigns targeting individuals and companies in the West since the outbreak of the Covid-19 pandemic.
Phishing attacks lure victims to a website that appears to be operated by a trusted entity, such as a bank, social media platform or other service.
The site, however, is phoney with fake content designed to persuade you to enter sensitive information such as a password or email address.
Attacks are most frequently spread over email but can also be contained in messages over chat apps such as WhatsApp.
It's recommended that users protect themselves from attacks by installing security software on their devices and setting up two-factor authentication on their online accounts.
Be suspicious of messages sent to you by strangers and avoid opening attachments or downloading files sent in messages or emails unless you completely trust whoever sent them.
Read More on The Sun
Moment plumes of smoke billow into the sky as 70 firefighters rush to blaze
Child dies after being found near Dover cliffs as cops launch investigation
If you’re worried that you might have fallen for a financial scam, the first thing you should do is contact your bank.
You should then report it to ActionFraud. Their website is actionfraud.police.uk, and their phone number is 0300 123 2040.
- Read all the latest Phones & Gadgets news
- Keep up-to-date on Apple stories
- Get the latest on Facebook, WhatsApp and Instagram
Best Phone and Gadget tips and hacks
Looking for tips and hacks for your phone? Want to find those secret features within social media apps? We have you covered…
- How to get your deleted Instagram photos back
- How to track someone on Google Maps
- How can I increase my Snapchat score?
- How can I change my Facebook password?
- How can I do a duet on TikTok?
- Here's how to see if your Gmail has been hacked
- How can I change my Amazon Alexa voice in seconds?
- What is dating app Bumble?
- How can I test my broadband internet speed?
- Here's how to find your Sky TV remote in SECONDS
We pay for your stories! Do you have a story for The Sun Online Tech & Science team? Email us at firstname.lastname@example.org
Source: Read Full Article