logo

WhatsApp device linking abused in account hijacking attacks

ID: f54e344d-8dcb-5d90-bc64-4d851f0557a3

STIX ID: report--f54e344d-8dcb-5d90-bc64-4d851f0557a3

Feed Name: Bleeping Computer

Threat Score
55/100

Date Published: 2025-12-17

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Threat actors running a campaign called "GhostPairing" are abusing WhatsApp’s legitimate device-linking workflow by luring victims to typosquatted Facebook-like pages that prompt them to enter pairing codes; once entered, attackers gain real-time access to messages and media, can impersonate users, and use compromised accounts to spread the scam. First observed in Czechia, the phishing campaign relies on social engineering rather than technical exploits; recommended mitigations include checking Settings → Linked Devices, blocking/reporting suspicious messages, and enabling two-factor authentication.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.