Based on the provided text, here's a summary of UNC7005's phishing and social engineering activities:
-
GLOBSEC Operation:
- Targets are lured to fill out forms with personal information.
- After registration, targets are prompted for identity verification.
- The page includes a script to detect and evade automated analysis efforts.
-
WhatsApp Device Linking Operations (May-June 2026):
- Phishing pages mimic WhatsApp to lure users into linking their accounts with an attacker-controlled device.
- Users are instructed to scan a QR code or enter a linking code to link their account.
- After successful linking, the page prompts users to join voice calls, encrypted chats, or download files.
-
Post-Compromise Actions:
- If the user joins a voice call, malicious JavaScript records audio and video from the target's device.
- The recorded data is sent to an attacker-controlled command-and-control (C2) endpoint.
Key Points:
-
Identity Verification:
- Targets are asked for personal information after filling out initial forms.
- This step likely involves verifying the user’s identity before proceeding with further actions.
Read the full article at Threat Intelligence
Want to create content about this topic? Use Nemati AI tools to generate articles, social posts, and more.



