Job Phishing Campaign Targeting Meta, WhatsApp & Instagram

Summary
The recent surge in job phishing campaigns targeting major platforms like Meta, WhatsApp, and Instagram has raised significant concerns recently. By analysing newly registered domains with keywords such as hire, apply and wajob a pattern of fraudulent activity has been uncovered. These domains, which began appearing in late 2024, are part of a coordinated effort to deceive job seekers by imitating legitimate recruitment processes.

| Domain | Registered | Expiry | Registrar Name |
| wahiringsolutionss.com | 2024-11-30 06:00:13+00:00 | 2025-11-30 06:00:13+00:00 | Ultahost, Inc. |
| messengertalentsearch.com | 2025-03-06 17:21:07+00:00 | 2026-03-06 17:21:07+00:00 | Ultahost, Inc. |
| wajobready.com | 2024-12-02 05:05:19+00:00 | 2025-12-02 05:05:19+00:00 | Ultahost, Inc. |
| wa-employerspace.com | 2025-03-22 15:46:22+00:00 | 2026-03-22 15:46:22+00:00 | Ultahost, Inc. |
| wahirelinks.com | 2024-12-02 05:05:06+00:00 | 2025-12-02 05:05:06+00:00 | Ultahost, Inc. |
| wa-employernet.com | 2025-03-22 15:14:50+00:00 | 2026-03-22 15:14:50+00:00 | Ultahost, Inc. |
| wajobopener.com | 2024-12-02 04:52:10+00:00 | 2025-12-02 04:52:10+00:00 | Ultahost, Inc. |
| wa-hrmatch.com | 2025-03-22 15:46:26+00:00 | 2026-03-22 15:46:26+00:00 | Ultahost, Inc. |
| apply-waexpert.com | 2025-03-31 19:02:57+00:00 | 2026-03-31 19:02:57+00:00 | Ultahost, Inc. |
| apply-waemployee.com | 2025-03-31 19:02:49+00:00 | 2026-03-31 19:02:49+00:00 | Ultahost, Inc. |
| apply-wacareer.com | 2025-03-31 19:02:43+00:00 | 2026-03-31 19:02:43+00:00 | Ultahost, Inc. |
| messengerhrnetwork.com | 2025-03-27 16:21:11+00:00 | 2026-03-27 16:21:11+00:00 | Ultahost, Inc. |
| messengercareerspot.com | 2025-03-27 16:21:07+00:00 | 2026-03-27 16:21:07+00:00 | Ultahost, Inc. |
| messenger-talentspot.com | 2025-03-27 16:21:02+00:00 | 2026-03-27 16:21:02+00:00 | Ultahost, Inc. |
| messenger-talentpool.com | 2025-03-27 16:20:58+00:00 | 2026-03-27 16:20:58+00:00 | Ultahost, Inc. |
| messenger-talentlink.com | 2025-03-27 16:20:53+00:00 | 2026-03-27 16:20:53+00:00 | Ultahost, Inc. |
| messenger-headhunt.com | 2025-03-27 16:20:48+00:00 | 2026-03-27 16:20:48+00:00 | Ultahost, Inc. |
| messenger-careerlink.com | 2025-03-27 16:20:43+00:00 | 2026-03-27 16:20:43+00:00 | Ultahost, Inc. |
| messenger-careerfinder.com | 2025-03-27 16:20:38+00:00 | 2026-03-27 16:20:38+00:00 | Ultahost, Inc. |
| messenger-careerboost.com | 2025-03-27 16:20:32+00:00 | 2026-03-27 16:20:32+00:00 | Ultahost, Inc. |
| apply-wawork.com | 2025-03-26 18:12:31+00:00 | 2026-03-26 18:12:31+00:00 | Ultahost, Inc. |
| apply-watalent.com | 2025-03-26 18:12:27+00:00 | 2026-03-26 18:12:27+00:00 | Ultahost, Inc. |
| apply-wastaffing.com | 2025-03-26 18:12:24+00:00 | 2026-03-26 18:12:24+00:00 | Ultahost, Inc. |
| apply-warecruit.com | 2025-03-26 18:12:18+00:00 | 2026-03-26 18:12:18+00:00 | Ultahost, Inc. |
| apply-wajobs.com | 2025-03-26 18:12:13+00:00 | 2026-03-26 18:12:13+00:00 | Ultahost, Inc. |
| apply-wahiring.com | 2025-03-26 18:12:04+00:00 | 2026-03-26 18:12:04+00:00 | Ultahost, Inc. |
| apply-wacareers.com | 2025-03-26 18:11:59+00:00 | 2026-03-26 18:11:59+00:00 | Ultahost, Inc. |
| schedule-watalent.com | 2025-03-24 22:47:03+00:00 | 2026-03-24 22:47:03+00:00 | Ultahost, Inc. |
| schedule-wastaffing.com | 2025-03-24 22:47:00+00:00 | 2026-03-24 22:47:00+00:00 | Ultahost, Inc. |
| schedule-wahiring.com | 2025-03-24 22:46:55+00:00 | 2026-03-24 22:46:55+00:00 | Ultahost, Inc. |
| schedule-wacareer.com | 2025-03-24 22:46:52+00:00 | 2026-03-24 22:46:52+00:00 | Ultahost, Inc. |
| wa-hrmatchmaker.com | 2025-03-22 15:46:30+00:00 | 2026-03-22 15:46:30+00:00 | Ultahost, Inc. |
| wa-workmatchpro.com | 2025-03-22 15:15:07+00:00 | 2026-03-22 15:15:07+00:00 | Ultahost, Inc. |
| wa-recruiterpro.com | 2025-03-22 15:14:59+00:00 | 2026-03-22 15:14:59+00:00 | Ultahost, Inc. |
| messengerworkfinder.com | 2025-03-19 14:26:44+00:00 | 2026-03-19 14:26:44+00:00 | Ultahost, Inc. |
| messengercareeradvice.com | 2025-03-19 14:26:39+00:00 | 2026-03-19 14:26:39+00:00 | Ultahost, Inc. |
| messenger-jobseekers.com | 2025-03-19 14:26:35+00:00 | 2026-03-19 14:26:35+00:00 | Ultahost, Inc. |
| messenger-jobconnect.com | 2025-03-19 14:26:31+00:00 | 2026-03-19 14:26:31+00:00 | Ultahost, Inc. |
| messenger-careerpath.com | 2025-03-19 14:26:25+00:00 | 2026-03-19 14:26:25+00:00 | Ultahost, Inc. |
| messenger-hirenow.com | 2025-03-14 15:06:37+00:00 | 2026-03-14 15:06:37+00:00 | Ultahost, Inc. |
| messenger-jobsolutions.com | 2025-03-14 14:26:42+00:00 | 2026-03-14 14:26:42+00:00 | Ultahost, Inc. |
| messenger-jobportal.com | 2025-03-14 14:18:01+00:00 | 2026-03-14 14:18:01+00:00 | Ultahost, Inc. |
| messenger-recruiter.com | 2025-03-14 14:10:14+00:00 | 2026-03-14 14:10:14+00:00 | Ultahost, Inc. |
| messenger-careering.com | 2025-03-14 13:49:41+00:00 | 2026-03-14 13:49:41+00:00 | Ultahost, Inc. |
| messenger-hiring.com | 2025-03-14 13:39:11+00:00 | 2026-03-14 13:39:11+00:00 | Ultahost, Inc. |
| messengertalenthub.com | 2025-03-06 17:21:02+00:00 | 2026-03-06 17:21:02+00:00 | Ultahost, Inc. |
| messengerhiretalent.com | 2025-03-06 17:20:54+00:00 | 2026-03-06 17:20:54+00:00 | Ultahost, Inc. |
| waworkready.com | 2024-11-30 05:34:46+00:00 | 2025-11-30 05:34:46+00:00 | Ultahost, Inc. |
| waworkmatch.com | 2024-11-30 05:34:41+00:00 | 2025-11-30 05:34:41+00:00 | Ultahost, Inc. |
| waexperrts.com | 2024-11-30 05:34:33+00:00 | 2025-11-30 05:34:33+00:00 | Ultahost, Inc. |
| wacareersgrowth.com | 2024-11-30 05:34:28+00:00 | 2025-11-30 05:34:28+00:00 | Ultahost, Inc. |
Based on the similarity of such pages it is likely to be associated with the same phishing kit with page title as Meta Pro Support: Facebook and Instagram and Meta .
Another interesting fact of this domains are being registered on Ultahost, Inc.(https://ultahost.com/) and most of the historical domains with similar patterns and live domains are hosted on IP address: 160.30.169[.]150 belongs to Cao Hoang Hai Technology Company Limited(AS152983), a less popular stub AS.

Stealing Facebook Credentials
All of the phishing sites are designed to steal credentials or personally identifiable information (PII) from victims, either through the registration page or the login page.

By utilizing the websocket, the threat actor behind this campaign can track specific victim sessions, making it easier to intercept OTP/2FA codes, which have short validity periods.


The domain under attack, spyder1279[.]blog, was registered in March of this year and is used for WebSocket communication with phishing sites. A quick passive DNS analysis of the IP address 173.46.80[.]222 reveals that two other domains(adevsoftinc[.]com & datacenterprocessing[.]com) are associated with it, likely owned by the threat actor.

Conclusion
This targeted phishing campaign represents a sophisticated and coordinated effort to exploit job seekers' trust in established platforms like Meta, WhatsApp, and Instagram. The registration of domains through a single registrar (Ultahost, Inc.) and their consistent hosting on infrastructure linked to Cao Hoang Hai Technology Company Limited (AS152983) it is likely a well-organized operation rather than disparate opportunistic campaigns.
Several key observations warrant attention from the cybersecurity community:
Pattern Recognition: The domain naming conventions consistently leverage trusted brand names (WhatsApp, Messenger) combined with employment-related terms (talent, career, hiring). This deliberate approach exploits the current job market anxiety and candidates' eagerness to find opportunities with prestigious companies.
Infrastructure Insights: The concentration of domains on a less popular stub AS and consistent use of the same registrar provides valuable indicators for detection and blocking. The shared infrastructure connecting the phishing sites to spyder1279.blog via WebSocket for real-time credential interception demonstrates technical sophistication beyond basic phishing operations.
Evolving Tactics: The implementation of WebSocket technology to track victim sessions and intercept time-sensitive OTP/2FA codes represents an advanced capability that significantly increases the threat actor's success rate against even security-conscious victims.
Community Note
Implement domain blocking for the identified patterns, particularly those featuring combinations of "wa," "messenger," "apply," "hire," and "job" with recently registered domains
Monitor for traffic to the identified command-and-control domains, especially spyder1279.blog, adevsoftinc.com, and datacenterprocessing.com for further activities or associations
This research will be updated as new information becomes available.




![Hunting Phishing URLs Made Easy: A Comprehensive Series [0x2]](/_next/image?url=https%3A%2F%2Fcdn.hashnode.com%2Fres%2Fhashnode%2Fimage%2Fupload%2Fv1741365952917%2Feca50620-1b58-4568-a794-02c34d0b2bbb.png&w=3840&q=75)
![Hunting Phishing URLs Made Easy: A Comprehensive Series [0x1]](/_next/image?url=https%3A%2F%2Fcdn.hashnode.com%2Fres%2Fhashnode%2Fimage%2Fupload%2Fv1741365407259%2F25792e26-5f85-4370-8eb5-47d81bf6bc23.png&w=3840&q=75)