Skip to main content

Command Palette

Search for a command to run...

Job Phishing Campaign Targeting Meta, WhatsApp & Instagram

Updated
6 min read
Job Phishing Campaign Targeting Meta, WhatsApp & Instagram

Summary

The recent surge in job phishing campaigns targeting major platforms like Meta, WhatsApp, and Instagram has raised significant concerns recently. By analysing newly registered domains with keywords such as hire, apply and wajob a pattern of fraudulent activity has been uncovered. These domains, which began appearing in late 2024, are part of a coordinated effort to deceive job seekers by imitating legitimate recruitment processes.

DomainRegisteredExpiryRegistrar Name
wahiringsolutionss.com2024-11-30 06:00:13+00:002025-11-30 06:00:13+00:00Ultahost, Inc.
messengertalentsearch.com2025-03-06 17:21:07+00:002026-03-06 17:21:07+00:00Ultahost, Inc.
wajobready.com2024-12-02 05:05:19+00:002025-12-02 05:05:19+00:00Ultahost, Inc.
wa-employerspace.com2025-03-22 15:46:22+00:002026-03-22 15:46:22+00:00Ultahost, Inc.
wahirelinks.com2024-12-02 05:05:06+00:002025-12-02 05:05:06+00:00Ultahost, Inc.
wa-employernet.com2025-03-22 15:14:50+00:002026-03-22 15:14:50+00:00Ultahost, Inc.
wajobopener.com2024-12-02 04:52:10+00:002025-12-02 04:52:10+00:00Ultahost, Inc.
wa-hrmatch.com2025-03-22 15:46:26+00:002026-03-22 15:46:26+00:00Ultahost, Inc.
apply-waexpert.com2025-03-31 19:02:57+00:002026-03-31 19:02:57+00:00Ultahost, Inc.
apply-waemployee.com2025-03-31 19:02:49+00:002026-03-31 19:02:49+00:00Ultahost, Inc.
apply-wacareer.com2025-03-31 19:02:43+00:002026-03-31 19:02:43+00:00Ultahost, Inc.
messengerhrnetwork.com2025-03-27 16:21:11+00:002026-03-27 16:21:11+00:00Ultahost, Inc.
messengercareerspot.com2025-03-27 16:21:07+00:002026-03-27 16:21:07+00:00Ultahost, Inc.
messenger-talentspot.com2025-03-27 16:21:02+00:002026-03-27 16:21:02+00:00Ultahost, Inc.
messenger-talentpool.com2025-03-27 16:20:58+00:002026-03-27 16:20:58+00:00Ultahost, Inc.
messenger-talentlink.com2025-03-27 16:20:53+00:002026-03-27 16:20:53+00:00Ultahost, Inc.
messenger-headhunt.com2025-03-27 16:20:48+00:002026-03-27 16:20:48+00:00Ultahost, Inc.
messenger-careerlink.com2025-03-27 16:20:43+00:002026-03-27 16:20:43+00:00Ultahost, Inc.
messenger-careerfinder.com2025-03-27 16:20:38+00:002026-03-27 16:20:38+00:00Ultahost, Inc.
messenger-careerboost.com2025-03-27 16:20:32+00:002026-03-27 16:20:32+00:00Ultahost, Inc.
apply-wawork.com2025-03-26 18:12:31+00:002026-03-26 18:12:31+00:00Ultahost, Inc.
apply-watalent.com2025-03-26 18:12:27+00:002026-03-26 18:12:27+00:00Ultahost, Inc.
apply-wastaffing.com2025-03-26 18:12:24+00:002026-03-26 18:12:24+00:00Ultahost, Inc.
apply-warecruit.com2025-03-26 18:12:18+00:002026-03-26 18:12:18+00:00Ultahost, Inc.
apply-wajobs.com2025-03-26 18:12:13+00:002026-03-26 18:12:13+00:00Ultahost, Inc.
apply-wahiring.com2025-03-26 18:12:04+00:002026-03-26 18:12:04+00:00Ultahost, Inc.
apply-wacareers.com2025-03-26 18:11:59+00:002026-03-26 18:11:59+00:00Ultahost, Inc.
schedule-watalent.com2025-03-24 22:47:03+00:002026-03-24 22:47:03+00:00Ultahost, Inc.
schedule-wastaffing.com2025-03-24 22:47:00+00:002026-03-24 22:47:00+00:00Ultahost, Inc.
schedule-wahiring.com2025-03-24 22:46:55+00:002026-03-24 22:46:55+00:00Ultahost, Inc.
schedule-wacareer.com2025-03-24 22:46:52+00:002026-03-24 22:46:52+00:00Ultahost, Inc.
wa-hrmatchmaker.com2025-03-22 15:46:30+00:002026-03-22 15:46:30+00:00Ultahost, Inc.
wa-workmatchpro.com2025-03-22 15:15:07+00:002026-03-22 15:15:07+00:00Ultahost, Inc.
wa-recruiterpro.com2025-03-22 15:14:59+00:002026-03-22 15:14:59+00:00Ultahost, Inc.
messengerworkfinder.com2025-03-19 14:26:44+00:002026-03-19 14:26:44+00:00Ultahost, Inc.
messengercareeradvice.com2025-03-19 14:26:39+00:002026-03-19 14:26:39+00:00Ultahost, Inc.
messenger-jobseekers.com2025-03-19 14:26:35+00:002026-03-19 14:26:35+00:00Ultahost, Inc.
messenger-jobconnect.com2025-03-19 14:26:31+00:002026-03-19 14:26:31+00:00Ultahost, Inc.
messenger-careerpath.com2025-03-19 14:26:25+00:002026-03-19 14:26:25+00:00Ultahost, Inc.
messenger-hirenow.com2025-03-14 15:06:37+00:002026-03-14 15:06:37+00:00Ultahost, Inc.
messenger-jobsolutions.com2025-03-14 14:26:42+00:002026-03-14 14:26:42+00:00Ultahost, Inc.
messenger-jobportal.com2025-03-14 14:18:01+00:002026-03-14 14:18:01+00:00Ultahost, Inc.
messenger-recruiter.com2025-03-14 14:10:14+00:002026-03-14 14:10:14+00:00Ultahost, Inc.
messenger-careering.com2025-03-14 13:49:41+00:002026-03-14 13:49:41+00:00Ultahost, Inc.
messenger-hiring.com2025-03-14 13:39:11+00:002026-03-14 13:39:11+00:00Ultahost, Inc.
messengertalenthub.com2025-03-06 17:21:02+00:002026-03-06 17:21:02+00:00Ultahost, Inc.
messengerhiretalent.com2025-03-06 17:20:54+00:002026-03-06 17:20:54+00:00Ultahost, Inc.
waworkready.com2024-11-30 05:34:46+00:002025-11-30 05:34:46+00:00Ultahost, Inc.
waworkmatch.com2024-11-30 05:34:41+00:002025-11-30 05:34:41+00:00Ultahost, Inc.
waexperrts.com2024-11-30 05:34:33+00:002025-11-30 05:34:33+00:00Ultahost, Inc.
wacareersgrowth.com2024-11-30 05:34:28+00:002025-11-30 05:34:28+00:00Ultahost, Inc.

Based on the similarity of such pages it is likely to be associated with the same phishing kit with page title as Meta Pro Support: Facebook and Instagram and Meta .

Image

Image

Another interesting fact of this domains are being registered on Ultahost, Inc.(https://ultahost.com/) and most of the historical domains with similar patterns and live domains are hosted on IP address: 160.30.169[.]150 belongs to Cao Hoang Hai Technology Company Limited(AS152983), a less popular stub AS.

http://caohoanghai.store/ screenshot

Stealing Facebook Credentials

All of the phishing sites are designed to steal credentials or personally identifiable information (PII) from victims, either through the registration page or the login page.

By utilizing the websocket, the threat actor behind this campaign can track specific victim sessions, making it easier to intercept OTP/2FA codes, which have short validity periods.

The domain under attack, spyder1279[.]blog, was registered in March of this year and is used for WebSocket communication with phishing sites. A quick passive DNS analysis of the IP address 173.46.80[.]222 reveals that two other domains(adevsoftinc[.]com & datacenterprocessing[.]com) are associated with it, likely owned by the threat actor.

Conclusion

This targeted phishing campaign represents a sophisticated and coordinated effort to exploit job seekers' trust in established platforms like Meta, WhatsApp, and Instagram. The registration of domains through a single registrar (Ultahost, Inc.) and their consistent hosting on infrastructure linked to Cao Hoang Hai Technology Company Limited (AS152983) it is likely a well-organized operation rather than disparate opportunistic campaigns.

Several key observations warrant attention from the cybersecurity community:

  1. Pattern Recognition: The domain naming conventions consistently leverage trusted brand names (WhatsApp, Messenger) combined with employment-related terms (talent, career, hiring). This deliberate approach exploits the current job market anxiety and candidates' eagerness to find opportunities with prestigious companies.

  2. Infrastructure Insights: The concentration of domains on a less popular stub AS and consistent use of the same registrar provides valuable indicators for detection and blocking. The shared infrastructure connecting the phishing sites to spyder1279.blog via WebSocket for real-time credential interception demonstrates technical sophistication beyond basic phishing operations.

  3. Evolving Tactics: The implementation of WebSocket technology to track victim sessions and intercept time-sensitive OTP/2FA codes represents an advanced capability that significantly increases the threat actor's success rate against even security-conscious victims.

Community Note

  • Implement domain blocking for the identified patterns, particularly those featuring combinations of "wa," "messenger," "apply," "hire," and "job" with recently registered domains

  • Monitor for traffic to the identified command-and-control domains, especially spyder1279.blog, adevsoftinc.com, and datacenterprocessing.com for further activities or associations

This research will be updated as new information becomes available.

More from this blog

H

Huskyscripts Blog - Threat Research

6 posts

Threat Research blog focusing on recent threats like phishing and adversary infrastructure hunting