Known malicious kitcriticalphishing

Chinese WhatsApp Impersonation — main.js

family: whatsapp-cn-bf71

5-host Chinese WhatsApp brand impersonation: it-web-whatsapp.hl.cn, llg-whatsapp.com.cn, etc. Third-region sister of whatsapp-bd-771c (Bangladesh) and whatsapp-pk-96b1 (Pakistan) — same kit-as-a-service operator targeting more countries.

Provenance

Added by: analyst
Added: 2026-05-27 07:09
5 hosts. WhatsApp impersonation, China cohort. Sister of bd-771c + pk-96b1.

Sightings (5)

HostScanScriptMatchWhen
whatsapp-web.xyz65a92f77https://whatsapp-web.xyz/static/js/main.6c724e39.jsbyte2026-05-24 10:11
it-web-whatsapp.hl.cnc19b3ebehttps://it-web-whatsapp.hl.cn/static/js/main.6c724e39.jsbyte2026-05-24 09:11
llg-whatsapp.com.cn3bdff214https://llg-whatsapp.com.cn/static/js/main.6c724e39.jsbyte2026-05-23 23:07
web.i-whatsapp.com.cnddc59d87https://web.i-whatsapp.com.cn/static/js/main.6c724e39.jsbyte2026-05-23 21:39
whatsappwt.com.cne79735c8https://whatsappwt.com.cn/static/js/main.6c724e39.jsbyte2026-05-23 05:34