{"id":9240,"date":"2025-12-16T10:03:42","date_gmt":"2025-12-16T10:03:42","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/12\/16\/new-ghostpairing-attack-let-attackers-gain-full-access-in-whatsapp-with-phone-number\/"},"modified":"2025-12-16T10:03:42","modified_gmt":"2025-12-16T10:03:42","slug":"new-ghostpairing-attack-let-attackers-gain-full-access-in-whatsapp-with-phone-number","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/12\/16\/new-ghostpairing-attack-let-attackers-gain-full-access-in-whatsapp-with-phone-number\/","title":{"rendered":"New GhostPairing Attack Let Attackers Gain Full Access in WhatsApp with Phone Number"},"content":{"rendered":"<p>    New GhostPairing Attack Let Attackers Gain Full Access in WhatsApp with Phone Number<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A newly discovered account takeover campaign targeting <a href=\"https:\/\/cybersecuritynews.com\/tag\/whatsapp\/\" target=\"_blank\" rel=\"noreferrer noopener\">WhatsApp users<\/a> demonstrates how attackers can compromise messaging accounts without stealing passwords or exploiting technical vulnerabilities.<\/p>\n<p>The threat, identified as the GhostPairing Attack, uses social engineering and WhatsApp\u2019s legitimate device linking feature to grant attackers complete access to victim accounts. <\/p>\n<p>The campaign first emerged in Czechia but shows no geographic limitations, with attackers using reusable kits to scale their operations across multiple countries and languages.<\/p>\n<p>The attack begins when victims receive messages from known contacts, typically suggesting they have found a photo. The message includes a link designed to appear as a Facebook content viewer. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjrfWBMU77MFIg2VUaoiPukxAZx-5Z6GMXBRRho1eZOkvjAfdeGaGsRxHS1qhypiHAQONZsqZffykzcWJkWfZ7rzMHTeOh7DDmuDmdzhKbYbFElKkb2tuHydyg08Y3b5TeEAA27ht29-gU8m5ho_4o407SL3M7PR_8dRUWt3kKhvk-Ge1vRQfsOnDEy6Rs\/s16000\/Lure%2520message%2520%28Source%2520-%2520Gen%2520Digital%29.webp?ssl=1\" alt=\"Lure message (Source - Gen Digital)\"><figcaption class=\"wp-element-caption\">Lure message (Source \u2013 Gen Digital)<\/figcaption><\/figure>\n<\/div>\n<p>When users click the link, they encounter a fake Facebook-themed page requesting verification before accessing content. <\/p>\n<p>This familiar interface creates a false sense of legitimacy that encourages users to complete the verification process without questioning its authenticity.<\/p>\n<p><span style=\"box-sizing: border-box; margin: 0px; padding: 0px;\">Gen Digital analysts and researchers\u00a0<a href=\"https:\/\/www.gendigital.com\/blog\/insights\/research\/ghostpairing-whatsapp-attack\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">discovered<\/a>\u00a0that the attack exploits WhatsApp\u2019s device pairing feature, which allows users to link additional devices, such as web browsers and desktop applications, to their accounts.<\/span><\/p>\n<p>Rather than relying on technical exploits or <a href=\"https:\/\/cybersecuritynews.com\/credential-theft-risks\/\" target=\"_blank\" rel=\"noreferrer noopener\">credential theft<\/a>, attackers trick users into willingly approving an unauthorized device connection.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-infection-mechanism\"><strong>Infection mechanism <\/strong><\/h2>\n<p>The infection mechanism relies on WhatsApp\u2019s phone number and numeric pairing code flow, making this attack particularly effective. <\/p>\n<p>When users enter their phone number on the <a href=\"https:\/\/cybersecuritynews.com\/browser-locker-ransomware-a-fake-page-that-threatens-user-and-demands-ransom\/\" target=\"_blank\" rel=\"noreferrer noopener\">fake page<\/a>, the attacker\u2019s infrastructure intercepts the request and forwards it to WhatsApp\u2019s legitimate device linking endpoint. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgN6abOZJFFC3bhC1RLZEtPKW2htWlV-iA2Re6qEKdnW1m5EsYELKULTEpZ-jJDg8WFI48qt52o4mi_yAPJ8DljFv-0dh0Qk3Z5GQ0T4JMCFPg9-hCzmsa13y09vV5iDwbPEkPQUNxpKTGFMOu1Z8tCZpyYx9iE3usCT8SrXXHq8t4OECTPvkoNvOx-0fY\/s16000\/Fake%2520Facebook%2520page%2520%28Source%2520-%2520Gen%2520Digital%29.webp?ssl=1\" alt=\"Fake Facebook page (Source - Gen Digital)\"><figcaption class=\"wp-element-caption\">Fake Facebook page (Source \u2013 Gen Digital)<\/figcaption><\/figure>\n<\/div>\n<p>WhatsApp generates a pairing code intended only for the account owner, but the attacker\u2019s website displays this code to the victim alongside instructions to enter it in WhatsApp to complete the login verification. <\/p>\n<p>From the victim\u2019s perspective, this appears identical to standard <a href=\"https:\/\/cybersecuritynews.com\/understanding-the-importance-of-two-factor-authentication-in-online-gaming\/\" target=\"_blank\" rel=\"noreferrer noopener\">two-factor authentication<\/a>. Once the victim enters the code in their actual WhatsApp application, they unknowingly approve the attacker\u2019s browser as a linked device. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEi-gwLu4M2F2lazWgC8Hg_KhmSdYICB2dmb2EOv4_eAxXLzPH0QZ3o8gh1jO4dzrEaQtpM6Hv40SWYiK-R6NvnScFo7EWQamjw9bBXVeLUuFSdc5JtfP9ZZKKMpe4Sz7zJ3ZOOPCRohCDP0CZ63wuOH6Wj7yMKZ_6wXxKK8hAs8pwzs4JCL7KZKLkppZz8\/s16000\/Code%2520sent%2520by%2520attackers%2520to%2520compromise%2520victim%25E2%2580%2599s%25E2%2580%2599%2520WhatsApp%2520account%2520%28Source%2520-%2520Gen%2520Digital%29.webp?ssl=1\" alt=\"Code sent by attackers to compromise victim\u2019s\u2019 WhatsApp account (Source - Gen Digital)\"><figcaption class=\"wp-element-caption\">Code sent by attackers to compromise victim\u2019s\u2019 WhatsApp account (Source \u2013 Gen Digital)<\/figcaption><\/figure>\n<\/div>\n<p>The attacker now has persistent access to all historical conversations, incoming messages, photos, videos, and sensitive information shared in the account, while remaining completely invisible to the account holder.<\/p>\n<p>The persistent nature of this access makes the attack particularly dangerous. Unlike traditional account hijacking that locks out legitimate users, GhostPairing allows attackers to observe conversations and gather intelligence indefinitely. <\/p>\n<p>Compromised accounts become propagation vectors, enabling attackers to send the same lure messages to the victim\u2019s contacts, creating a snowball effect that multiplies the attack\u2019s reach. <\/p>\n<p>Users can protect themselves by regularly checking their linked devices in WhatsApp Settings and removing unknown sessions, treating any external requests to scan QR codes or enter pairing codes as immediately suspicious, and enabling Two-Step Verification for additional account security.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 92%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/new-ghostpairing-attack-let-attackers-gain-full-access\/\">New GhostPairing Attack Let Attackers Gain Full Access in WhatsApp with Phone Number<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/new-ghostpairing-attack-let-attackers-gain-full-access\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>New GhostPairing Attack Let Attackers Gain Full Access in WhatsApp with Phone Number A newly discovered account takeover campaign targeting WhatsApp users demonstrates how attackers can compromise messaging accounts without stealing passwords or exploiting technical vulnerabilities. The threat, identified as the GhostPairing Attack, uses social engineering and WhatsApp\u2019s legitimate device linking feature to grant attackers [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-9240","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9240"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=9240"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9240\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=9240"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=9240"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=9240"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}