PULSE NAME
Russian campaign targeting Romanian WhatsApp numbers
WHITE AlienVault 2025-02-28 Modified: 2025-03-03
27
IOCs
MEDIUM VOLUME
A campaign originating from Russia has been identified, targeting Romanian WhatsApp users. The operation involves sending messages to victims, encouraging them to vote in a fake contest. When users click on the provided link, they are prompted to enter their WhatsApp number and an 8-character code, which grants the attackers access to the victim's account. The campaign uses multiple domains with Romanian-themed names, and evidence suggests previous targeting of English and Turkish-speaking users. The attackers exploit compromised accounts to spread the malicious messages further, potentially leading to account loss due to spamming. Users are advised against entering codes from suspicious websites to protect their WhatsApp accounts.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
Indicators of Compromise (27)
All domain
TYPEINDICATORDESCRIPTIONCREATED
domain concursdedans.com 2025-02-28
domain concursiarna.com 2025-02-28
domain concursro.com 2025-02-28
domain coonnkurenta.top 2025-02-28
domain danccingro.com 2025-02-28
domain dancechoise.com 2025-02-28
domain dancefesting.top 2025-02-28
domain danceiivot.top 2025-02-28
domain dancerofest.com 2025-02-28
domain dancersfes.com 2025-02-28
domain dancersro.com 2025-02-28
domain dancevotr.top 2025-02-28
domain danciingro.com 2025-02-28
domain dancingro.com 2025-02-28
domain dancingvot.top 2025-02-28
domain feastdance.top 2025-02-28
domain festdance.com 2025-02-28
domain rocondance.com 2025-02-28
domain rodaciing.com 2025-02-28
domain rodancee.com 2025-02-28
domain rodancehit.com 2025-02-28
domain rodancing.com 2025-02-28
domain rodence.com 2025-02-28
domain rofesting.com 2025-02-28
domain showdance.top 2025-02-28
domain starsdance.top 2025-02-28
domain votingdance.top 2025-02-28