New GhostPairing Attack Let Attackers Gain Full Access in WhatsApp with Phone Number
A recent account takeover campaign known as the GhostPairing Attack targets WhatsApp users . This attack enables unauthorized access to messaging accounts through social engineering and WhatsApp's device linking feature, without exploiting technical…
A recent account takeover campaign known as the GhostPairing Attack targets WhatsApp users . This attack enables unauthorized access to messaging accounts through social engineering and WhatsApp's device linking feature, without exploiting technical vulnerabilities or stealing passwords.
The attack, initially detected in Czechia, has demonstrated scalability across various countries. Attackers utilize reusable kits, allowing operations in multiple languages.
The attack commences with victims receiving messages from known contacts, usually suggesting they have found a photo. The message includes a link that mimics a Facebook content viewer.
Upon clicking the link, users are directed to a fake Facebook-themed page that requests verification. This familiar interface fosters trust, prompting users to complete the process without verifying its legitimacy.
A recent account takeover campaign known as the GhostPairing Attack targets WhatsApp users .
Researchers from Gen Digital have identified that the attack leverages WhatsApp's device pairing feature, which permits additional devices like web browsers and desktop applications to link to user accounts. Attackers deceive users into approving unauthorized device connections.
The attack's effectiveness stems from WhatsApp's phone number and numeric pairing code flow. When victims input their phone numbers on the fake page, the attacker's infrastructure intercepts the request and forwards it to WhatsApp's legitimate device linking endpoint.
WhatsApp generates a pairing code intended for the account owner, but the attacker's site displays this code, instructing victims to enter it into WhatsApp to complete the login verification. This process appears akin to standard two-factor authentication . Once entered, the victim unknowingly authorizes the attacker's browser as a linked device.
The attacker gains persistent access to all historical conversations, incoming messages, and shared sensitive information, remaining undetected by the account holder.
Regularly check linked devices in WhatsApp Settings and remove unknown sessions. Treat external requests to scan QR codes or enter pairing codes as suspicious. Enable Two-Step Verification for additional account security.
Based on reporting by Cyber Security News.
