Understanding this attack requires mapping the exact sequence of technical events against the psychological pressure applied by the caller.
| Phase | Attacker Action | Vulnerability Exploited |
|---|---|---|
| 1. Contact & Pretext | Initiates video call using trusted profile; discusses marketplace listing. | False sense of safety created by face-to-face video interaction. |
| 2. The Instruction | Feigns an app error; guides victim to tap the screen share button. | Unfamiliarity with platform UI icons and broadcast warnings. |
| 3. The Interception | Requests login for WhatsApp or bank; captures SMS code via banner preview. | Active notification banners appearing over full-screen broadcasts. |
| 4. Total Takeover | Enters intercepted OTP; activates hardware PIN; severs victim session. | Absence of secondary hardware security keys or account PIN locks. |
Data from regional cybercrime units shows that account takeover incidents using live broadcast features surged over 140% between 2024 and 2026. The tactic bypasses traditional anti-phishing software because no malicious domain is visited. The victim's phone behaves normally; it simply mirrors its own output to an adversary.