WhatsApp, Japan, and a 500% Traffic Spike! 💹 🚨

To be honest, we thought threat actors were tripping when we saw a new WhatsApp phishing campaign targeting Japanese citizens. Don't they know LINE is the app in Japan? Well, we were surprised because this campaign is actually working…

The campaign doesn't only impersonate WhatsApp through its phishing page, but also through the lookalike domains it uses. Around 2k "WhatsApp" domain name variations are involved. The actor also leverages RDGAs – mostly for subdomains. Domains like web-rka-whatsapp[.]com[.]cn have up to 32 RDGA subdomains!

Upon visiting one of these lookalike domains, the user is fingerprinted and only forwarded to the phishing page if they match the intended profile — otherwise they get redirected to sites like bing[.]com or microsoft[.]com. As we show at the image below (with an AI-translated version), the malicious landing page simulates the WhatsApp login screen and encourages victims to scan a malicious QR code with their phone to log in.

When we found the cluster, we genuinely didn't think this campaign would land in Japan — but we were wrong. In the last 6 months, traffic to these domains has increased more than 500%, and it continues to rise.

What impact would these top quality lookalikes have if the campaigns were directed at countries where WhatsApp is actually the preferred messaging app?

Domain sample:
whatsappweb[.]net
whatapapp[.]com
whatsptapp[.]com
leropaxi-whatsapp[.]com[.]cn

#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #Phishing #Quishing #WhatsApp #LINE #Japan #脅威情報 #フィッシング詐欺 #QRコード詐欺 #DNSセキュリティ #Infoblox脅威情報 #WhatsApp #LINEセキュリティ #日本 #サイバーセキュリティ

LINE「衛星モード」展開【v26.6.0】

2026 年 5 月 6 日(水)前後、Android / iOS 版「LINE」アプリにアプリバージョン v26.6.0 アップデートが配信開始され、ついに Android / iOS 版「LINE」アプリに「衛星モード」が追加。Android / iOS 版「LINE」アプリが「Starlink」衛星通信に対応し、ついに「衛星モード」でのメッセージ送受信や位置情報共有、「LINE 安否確認」などを利用可能に。「Pixel 9」シリーズ以降などの衛星通信に対応する Android / iOS デバイスにて、モバイルネットワーク / Wi-Fi 通信に接続できない圏外 / オフラインの状況かつ「docomo Starlink Direct」「au Starlink Direct」「SoftBank Starlink Direct」のいずれかを利用できる状態であれば、自動で有効化。

Jetstream