A WhatsApp scam is spreading through compromised accounts by asking targets to “vote for my friend” in online contests such as ballet performances, dog competitions, and school events. Victims receive the message from trusted contacts whose accounts have already been hijacked, then are redirected to pages that imitate WhatsApp or abuse the legitimate wa.me domain to trick them into linking an attacker-controlled device to their account instead of entering credentials.
By abusing WhatsApp’s Linked Devices feature, the attackers gain persistent, real-time access to messages and conversations without triggering password-reset warnings or failed-login alerts. The access lets them continue sending scam messages from the victim’s account and, in some cases, solicit money from friends and family; the main visible sign of compromise may be an unfamiliar device listed in the account’s linked devices settings. Researchers said the technique resembles GhostPairing, but uses contest-voting social engineering to drive account takeover.

Get the infrastructure and lures behind it.
2 events from the most recent confirmed update back to the earliest known activity.
Malwarebytes reported a WhatsApp scam campaign in which messages from already-compromised contacts asked targets to vote for a friend or acquaintance in an online contest. The campaign tricked victims into linking an attacker-controlled device to their WhatsApp account, enabling message access and further scam propagation.
Researchers documented abuse of WhatsApp's linked devices mechanism under the name GhostPairing. The technique used fake photo-viewer pages rather than the later contest-voting lure.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.