A new WhatsApp account takeover campaign, dubbed the GhostPairing attack, leverages social engineering to trick users into granting attackers access to their accounts without requiring password theft or SIM swapping. Victims receive a message from a trusted contact, typically stating "Hey, I just found your photo!" and containing a link that appears to be a Facebook preview. When the link is clicked, users are directed to a convincing fake Facebook page that prompts them to "verify" their identity. This process covertly guides the victim through WhatsApp's device-linking flow, resulting in the attacker's device being added as a linked device on the victim's account.
The attack exploits WhatsApp's legitimate device pairing feature, making the compromise appear as a user-approved action. The campaign was first observed in Czechia, with messages sent from compromised accounts to local contacts, and the infrastructure relies on a network of lookalike domains designed to mimic Facebook. Security researchers emphasize that there is no password theft or SIM swap involved; instead, the attack relies entirely on user manipulation. Users are advised to be cautious of unexpected messages, even from known contacts, and to scrutinize any requests to verify or link devices within WhatsApp.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Gen Digital publicly disclosed the GhostPairing attack, describing how attackers can gain persistent access to WhatsApp accounts without stealing passwords or performing SIM swaps. The disclosure detailed the campaign's propagation through compromised accounts, use of lookalike domains, and the broader risk posed by similar pairing flows on other platforms.
Gen Digital reported first observing a WhatsApp account-takeover campaign in Czechia that abused the platform's legitimate linked-device pairing flow. The attack used messages from compromised contacts and fake Facebook/Meta-themed pages to trick victims into linking an attacker-controlled device.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
malwarebytes.com
Open sourcecsoonline.com
Open sourcesecurityonline.info
Open sourcebleepingcomputer.com
Open sourceblog.avast.com
Open sourcegendigital.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.