Categories: Mobile Attacks

WhatsApp scam – Advertising Netflix Subscription free for a year

[jpshare]These days it winds up plainly normal as we see a huge increase with Scam message in Whatsapp, here is another WhatsApp scam – Advertising Netflix Subscription free for a year.

For this new Whatsapp trick, fraudsters are utilizing this outstanding TV mark as the trap to spread the attack.

Initial Scam Message

If you have received the message even from a reliable contact don’t click or don’t share the link.

The message has all the earmarks of being from Netflix, however, have close look it demonstrates a shortened URL which takes clients to different sites not identified as Netflix.

Also, the image appears in different languages Spanish, English, and Portuguese.

Spanish
English
Portuguese

Multilingual Fake page

User’s on clicking the link will take to the page that not belongs to Netflix as like the malicious URL the multilingual.

Another inquisitive truth is that the page has the ability to recognize the language of the device and can change its language consequently.

This malicious page guarantees that if the request was sent to 10 individuals then Netflix service will be accessible free for a year.

The victim is redirected to pages that falsely claim that they are on the “last stride” to accomplish enactment when is truly happening that they are taking information from clients according to ESET blog post.

Mitigations

  • If you already shared with anyone, ESET advising users to contact them and let them know about the incident.
  • Did you provide your telephone number? Check wit your service provider that you are not added to any premium service.
  • If any application downloaded from the URL, uninstall them immediately.

Also Read

Gurubaran

Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Recent Posts

Blind Eagle Targets Organizations with Weaponized .URL Files to Steal User Hashes

In a significant development in the cybersecurity landscape, APT-C-36, more commonly known as Blind Eagle,…

5 hours ago

INE Security Alert: Using AI-Driven Cybersecurity Training to Counter Emerging Threats

As Artificial Intelligence (AI)-powered cyber threats surge, INE Security, a global leader in cybersecurity training…

5 hours ago

Apache NiFi Vulnerability Exposes MongoDB Credentials to Attackers

A critical security vulnerability has been identified in Apache NiFi, a popular open-source data integration…

5 hours ago

86,000+ Healthcare Staff Records Exposed Due to AWS S3 Misconfiguration

A non-password-protected database belonging to ESHYFT, a New Jersey-based HealthTech company, was recently discovered by…

5 hours ago

Microsoft Finally Patches 2-Year-Old Windows Kernel Security Flaw

Microsoft has released a critical patch for a 2-year-old Windows kernel security vulnerability. This vulnerability,…

5 hours ago

Hackers Exploiting JSPSpy To Manage Malicious Webshell Networks

Cybersecurity researchers have recently identified a cluster of JSPSpy web shell servers featuring an unexpected…

6 hours ago