A sophisticated phishing campaign has been targeting WhatsApp users globally by leveraging fake online voting pages as a social engineering lure. Attackers initiate contact through personalized messages, often impersonating friends or relatives whose accounts have already been compromised, and request recipients to vote for a contestant in a fabricated competition. The phishing messages are distributed via WhatsApp groups, private chats, and other social networks, increasing their reach and credibility. Victims are directed to convincingly designed phishing websites that mimic legitimate voting polls, complete with real participant photos, vote buttons, and dynamic counters to enhance authenticity. These phishing sites are produced in multiple languages, including English, Spanish, German, Turkish, Danish, and Bulgarian, indicating a broad, international scope and the likely use of AI-driven phishing kits. Upon clicking the vote button, users are prompted to provide sensitive information, which can lead to account compromise and further propagation of the scam through hijacked accounts. The campaign demonstrates a shift in phishing tactics from traditional email-based attacks to mobile-first platforms such as WhatsApp, SMS, and other messaging services. This trend is corroborated by industry data showing that 41% of phishing incidents now employ multichannel approaches, including smishing, vishing, and quishing. The move to mobile platforms makes these attacks harder to detect and prevent, as they exploit the trust and immediacy associated with personal messaging apps. Security experts warn that these mobile phishing campaigns are more likely to succeed due to their personalized nature and the difficulty users face in distinguishing legitimate requests from fraudulent ones. In response, organizations are adopting AI-driven security solutions that analyze message content and intent in real time to identify and block social engineering attempts before users are compromised. The ongoing evolution of phishing tactics underscores the need for heightened user awareness, robust mobile security measures, and continuous monitoring of emerging threats targeting messaging platforms. Enterprises are advised to educate employees about the risks of unsolicited voting requests and to implement technical controls that can detect and mitigate phishing attempts across all communication channels. The widespread nature of this campaign highlights the importance of a multi-layered defense strategy that addresses both technological and human vulnerabilities. As attackers continue to innovate, proactive threat intelligence and adaptive security solutions remain critical to protecting users from account takeover and data theft. The incident serves as a reminder that social engineering remains a potent tool for cybercriminals, especially when combined with convincing pretexts and advanced phishing infrastructure. Organizations and individuals alike must remain vigilant against evolving phishing schemes that exploit trust and social connections on mobile platforms.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Security coverage described a phishing scheme spreading via WhatsApp messages that impersonate online voting or contest campaigns to trick users into clicking malicious links and surrendering data or account access. The references frame this as part of a broader shift of phishing activity from email toward mobile messaging platforms.
Researchers documented a WhatsApp hijacking campaign targeting Romanian users with fake voting or prize-contest messages sent from compromised contacts. The operation used malicious sites to trick victims into linking their WhatsApp accounts to attacker-controlled devices, and infrastructure clues such as Russian-language settings and VK references suggested a Russian origin.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
kaspersky.com
Open sourcedarkreading.com
Open sourcecybergeeks.tech
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.