GhostPairing Attack Exposes WhatsApp Accounts to Full Takeover via Phone Numbers
Cybersecurity Overview of the GhostPairing Attack A recent campaign known as the "GhostPairing Attack" has been identified, allowing unauthorized access to WhatsApp accounts without the need for password theft or SIM swaps. This attack leverages WhatsApp's device pairing feature to…

Cybersecurity
Overview of the GhostPairing Attack
A recent campaign known as the "GhostPairing Attack" has been identified, allowing unauthorized access to WhatsApp accounts without the need for password theft or SIM swaps. This attack leverages WhatsApp's device pairing feature to gain control over user accounts.
Technical Details
The attack initiates with a misleading message sent via WhatsApp. Users receive messages appearing to be from known contacts, containing a link that resembles a Facebook preview. Upon clicking, users are directed to a page mimicking Facebook's login interface, prompting them to verify their identity. This page acts as a control panel for the attacker, forwarding the user's information to WhatsApp's legitimate device linking system.
The attacker intercepts the authentication code generated by WhatsApp, which is then presented to the victim as part of the verification process. This results in the attacker's device being registered as a linked device to the victim's account, effectively allowing the attacker access to the account.
This attack leverages WhatsApp's device pairing feature to gain control over user accounts.
Infrastructure and Impact
Initially detected in Czechia, the attack uses a series of similar domains, such as photobox[.]life and postsphoto[.]life, indicating a scalable and adaptable threat. Once attackers link their device, they can access historical conversations, real-time messages, and media. They can also propagate the attack by sending lures to the victim's contacts.
This access remains until the victim manually removes the unauthorized devices from their account settings.
Recommendations for Protection
- Regularly review linked devices in WhatsApp Settings → Linked Devices and remove any unrecognized sessions.
- Be cautious of external requests to scan QR codes or input numeric codes.
- Enable WhatsApp's Two-Step Verification for additional security.
- Share awareness of the GhostPairing attack with contacts to reduce susceptibility.
It's important to note that similar attacks could target other platforms utilizing device pairing and authentication codes. Enhanced transparency and visibility of connected sessions are essential for preventing such account compromises.




