Menu

  • Alerts
  • Incidents
  • News
  • APTs
  • Cyber Decoded
  • Cyber Hygiene
  • Cyber Review
  • Cyber Tips
  • Definitions
  • Malware
  • Threat Actors
  • Tutorials

Useful Tools

  • Password generator
  • Report an incident
  • Report to authorities
No Result
View All Result
CTF Hack Havoc
CyberMaterial
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
Hall of Hacks
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
No Result
View All Result
Hall of Hacks
CyberMaterial
No Result
View All Result
Home Alerts

Chrome Extensions Hijack WhatsApp Web

October 20, 2025
Reading Time: 3 mins read
in Alerts
Experian Fined For Data Collection

Cybersecurity researchers have uncovered a sophisticated and long-running spam campaign that has been leveraging 131 rebranded clones of a specific WhatsApp Web automation extension available in the Google Chrome Web Store. The campaign, which has been active for at least nine months, is designed specifically to blast outbound messages to Brazilian users at a scale that successfully bypasses WhatsApp’s inherent rate limits and anti-spam enforcement mechanisms.

While the extensions are not classic malware, they function as high-risk spam automation tools that abuse platform rules by injecting code directly into the WhatsApp Web page, running alongside its native scripts to automate bulk outreach and scheduling.All 131 spamware extensions share an identical underlying codebase, design patterns, and infrastructure, according to an analysis by the supply chain security company Socket. Collectively, these browser add-ons have amassed approximately 20,905 active users who utilize them for automated messaging.

Though the extensions are branded with different names and logos—such as YouSeller, performancemais, Botflow, and ZapVende—the vast majority were published by the same developer accounts, “WL Extensão” and “WLExtensao.” This difference in branding appears to be the result of a franchise or reseller model advertised by a company named DBX Tecnologia, which encourages affiliates to rebrand and sell clones of the original extension, promising significant recurring revenue.The extensions are promoted to users as legitimate customer relationship management (CRM) tools for WhatsApp, with descriptions touting features like an “intuitive CRM,” “message automation,” “bulk messaging,” and a “visual sales funnel” to help users maximize sales.

For example, the description for “ZapVende” explicitly states the tool can turn WhatsApp into a “powerful sales and contact management tool” to help organize customer service and track leads. DBX Tecnologia actively advertises a white-label program, allowing partners to invest in rebranding the extension and selling it under their own name, promising returns ranging from R$30,000 to R$84,000.This practice is in direct violation of Google’s Chrome Web Store Spam and Abuse policy, which prohibits developers and their partners from submitting multiple extensions that offer duplicate functionality.

Researchers noted that the cluster is composed of near-identical copies spread across various publisher accounts and is explicitly marketed for bulk, unsolicited outreach. The core goal is to keep these large-scale spam campaigns running consistently while effectively evading anti-spam systems. Furthermore, DBX Tecnologia has even been observed publishing YouTube videos that explicitly instruct users on how to bypass WhatsApp’s anti-spam algorithms when using their extensions, underscoring the malicious intent behind the campaign. The disclosure of this expansive Chrome Web Store spam campaign targeting Brazilians follows recent warnings from other security firms regarding a separate, large-scale operation.

That campaign, which involves a WhatsApp worm dubbed SORVEPOTEL, is actively distributing a sophisticated banking trojan known as Maverick, highlighting a current surge in targeted cyber threats against users in Brazil. The discovery emphasizes a coordinated, multi-pronged effort by malicious actors to abuse popular platforms and circumvent security controls for financial and spam-related gain.

Reference:

  • Over 100 Chrome Extensions Abused To Hijack WhatsApp Web In Major Spam Campaign
Tags: Cyber AlertsCyber Alerts 2025CyberattackCybersecurityOctober 2025
ADVERTISEMENT

Related Posts

Experian Fined For Data Collection

TikTok Videos Driving Infostealer Attacks

October 20, 2025
Experian Fined For Data Collection

Google Ads Used To Push Fake Software

October 20, 2025
Sothebys Data Breach Exposes Customers

Microsoft Pulls 200 Suspicious Certificates

October 17, 2025
Sothebys Data Breach Exposes Customers

NK Hackers Hide Malware In Blockchain

October 17, 2025
Sothebys Data Breach Exposes Customers

Hackers Spread Malware With Blockchain

October 17, 2025

Fortinet And Ivanti Patch Severe Flaws

October 16, 2025

Latest Alerts

TikTok Videos Driving Infostealer Attacks

Chrome Extensions Hijack WhatsApp Web

Google Ads Used To Push Fake Software

Microsoft Pulls 200 Suspicious Certificates

NK Hackers Hide Malware In Blockchain

Hackers Spread Malware With Blockchain

Subscribe to our newsletter

    Latest Incidents

    AWS Outage Disrupts Major Services

    Envoy Air Hit By Oracle System Hack

    F5 Breach Hits 262000 BIGIP Systems

    Pro Hamas Hackers Target Airport Speakers

    Prosper Breach Hits 17 Million Accounts

    Sothebys Data Breach Exposes Customers

    CyberMaterial Logo
    • About Us
    • Contact Us
    • Jobs
    • Legal and Privacy Policy
    • Site Map

    © 2025 | CyberMaterial | All rights reserved

    Welcome Back!

    Login to your account below

    Forgotten Password?

    Retrieve your password

    Please enter your username or email address to reset your password.

    Log In

    Add New Playlist

    No Result
    View All Result
    • Alerts
    • Incidents
    • News
    • Cyber Decoded
    • Cyber Hygiene
    • Cyber Review
    • Definitions
    • Malware
    • Cyber Tips
    • Tutorials
    • Advanced Persistent Threats
    • Threat Actors
    • Report an incident
    • Password Generator
    • About Us
    • Contact Us
    • Advertise with us

    Copyright © 2025 CyberMaterial