GhostPairing campaign abuses WhatsApp device linking to hijack accounts (Pierluigi Paganini- Security Affairs)

Attackers are exploiting WhatsApp’s device-linking feature to hijack accounts using pairing codes in a campaign dubbed GhostPairing, without requiring authentication. Gen Digital first observed the GhostPairing campaign in Czechia, but warns that it can spread globally via compromised accounts. The attack chain begins with victims receiving a message, such as “Hey, I just found your photo!”, from a trusted contact. The message contains a link with a Facebook-style preview.

GhostPairing campaign abuses WhatsApp device linking to hijack accounts

Latest articles

Related articles