Skip to content
July 21, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • News
  • Cybercriminals
  • GhostPairing: New Attack Hijacks WhatsApp via Linked Devices, Tricking Users with Fake Facebook QR Code
  • Cybercriminals

GhostPairing: New Attack Hijacks WhatsApp via Linked Devices, Tricking Users with Fake Facebook QR Code

Do Son December 17, 2025 3 minutes read
0
WhatsApp antitrust API probe India SIM-Binding Mandate Messaging App KYC WhatsApp DMA Interoperability BirdyChat Haiket Denmark Social Media Ban CVE-2025-55177 WhatsApp vulnerability, zero-click flaw npm Malware, System Wipe WhatsApp Windows App, WebView2 Downgrade WhatsApp Ban, US House NSO WhatsApp, Pegasus Spyware WhatsApp iPad iPadOS app
Add Daily CyberSecurity as a preferred source on Google

A deceptive new cyberattack campaign is turning one of WhatsApp’s most convenient features into a weapon, allowing hackers to take full control of user accounts without ever stealing a password or touching a SIM card. Dubbed “GhostPairing” by researchers at Gen Digital, the attack relies not on sophisticated code exploits, but on a clever manipulation of user trust and the “linked devices” function found in modern messaging apps.

The attack typically begins with a message from a compromised contact, utilizing a hook that is almost impossible for many to ignore. The victim receives a text saying something innocuous like, “Hey, I just found your photo!” accompanied by a link that generates a legitimate-looking preview, often imitating a Facebook post.

“The message includes a link that appears as a Facebook style preview. When users open it, they see a page that imitates a Facebook viewer and asks them to ‘verify’ before they can see the content”.

This “verification” step is the trap. The page guides the user through a quick sequence of actions—steps that seem like standard security checks but are actually authorizing a hostile takeover.

WhatsApp GhostPairing, Linked Device Hijack
Lure message received by the victim | Image: Gen Digital

Unlike traditional attacks that try to harvest login credentials, GhostPairing tricks the victim into essentially handing over the keys to the castle. The attackers use the verification process to initiate WhatsApp’s own device pairing flow.

By prompting the user to scan a QR code or enter a numeric code under the guise of verifying their identity, the victim unwittingly links the attacker’s browser to their WhatsApp account.

“There is no password theft or SIM swap – instead, the user approves the attacker themselves by entering a pairing code that looks like normal verification”.

Once the link is established, the attacker has a persistent, invisible window into the victim’s digital life. They can send messages, read private conversations, and spread the malware further—all while the legitimate owner continues to use their phone, oblivious to the “ghost” device running in the background.

The genius—and danger—of the GhostPairing attack lies in its simplicity. It does not attempt to break encryption or bypass two-factor authentication in the traditional sense. Instead, it exploits the intended design of the software.

“The campaign described here illustrates a subtle shift in how some attackers operate. Instead of breaking cryptography or circumventing authentication, they use the product as designed and persuade users to cooperate at just the right moment”.

Gen Digital researchers warn that this technique represents a broader threat to the digital ecosystem, as many platforms now prioritize seamless multi-device connectivity. “The design pattern that made GhostPairing possible is not unique to WhatsApp. Any platform that combines very easy pairing with low visibility of linked devices gives attackers something to work with”.

The campaign was first detected in Czechia but has the potential to spread globally due to its language-agnostic methodology. The incident serves as a stark reminder that in an era of convenient connectivity, a single moment of inattention can have lasting consequences.

“GhostPairing should be read as a warning, not just a WhatsApp incident. The more our digital lives depend on quick QR scans and ‘approve on your phone’ flows, the more important it becomes to design these steps so that a single moment of inattention does not quietly create a ghost device that lives in the background for months”.

Related Posts:

  • QR Codes Coming to Linux Kernel Panics with 6.12 Release
  • The Hidden Danger of PDF Files with Embedded QR Codes, Researchers Warn
  • QR Code Phishing Attacks Escalate: Sophisticated Campaign Targets Chinese Citizens
  • “Unicode QR Code Phishing”: The New Threat You Need to Know

Get Zero-Hour Vulnerability Alerts

Critical CVEs, CVSS scores, and PoC updates — straight to your inbox every week.


We respect your inbox. Unsubscribe anytime.

Related coverage

  • KillSec Ransomware Strikes Brazilian Healthcare Provider, Exposing Patient Data
  • Cybersecurity Pros Admit to Moonlighting as BlackCat Ransomware Affiliates
  • ShadowSilk Unmasked: The Hybrid Espionage Group Targeting Central Asian Governments
  • Twitter Ad Loophole Exploited in iToken Crypto Scam Spoofing CNN and Apple Brands
  • Deepfakes and Deception: The Rise of Synthetic Identities in Remote Work
Track all actively exploited CVEs →

Support Our Threat Intelligence

If you find our CVE report and cybersecurity news helpful, consider supporting our work.

Buy Me a Coffee Logo Buy Me a Coffee PayPal
Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Share this article:

Facebook Post LinkedIn Telegram
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: Account Hijack Gen Digital GhostPairing Linked Devices phishing QR Code Scam User Trust WhatsApp

Leave a Reply Cancel reply

You must be logged in to post a comment.

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🚨 Active Exploits in the Wild

  • CVE-2026-50522CVSS 9.8
    Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
    Admin intel📅 Updated: Jul 21, 2026
  • CVE-2026-63030CVSS 9.8
    WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion...
    Admin intelCISA KEV📅 Added to KEV: Jul 21, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-60137CVSS 5.9
    WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter...
    Admin intelCISA KEV📅 Added to KEV: Jul 21, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-0770CVSS 9.8
    Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers...
    CISA KEV📅 Added to KEV: Jul 21, 2026
  • CVE-2021-27137CVSS 8.1
    An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality...
    CISA KEV📅 Added to KEV: Jul 21, 2026
  • CVE-2026-6875CVSS 9.5
    ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability...
    Admin intel📅 Updated: Jul 18, 2026
  • CVE-2026-39808CVSS 9.8
    A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox...
    CISA KEV📅 Added to KEV: Jul 16, 2026
  • CVE-2026-25089CVSS 9.8
    A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox...
    CISA KEV📅 Added to KEV: Jul 16, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-64825CVSS 9.3
    Home Assistant Core before 2026.6.0 contains a path traversal vulnerability that allows...
  • CVE-2026-28321CVSS 9.1
    SolarWinds Serv-U is affected by a broken access control vulnerability that could...
  • CVE-2026-28317CVSS 9.1
    SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability...
  • CVE-2026-28316CVSS 9.1
    SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability...
  • CVE-2026-28314CVSS 9.1
    SolarWinds Serv-U is affected by an insecure direct object reference vulnerability that...
  • CVE-2026-28313CVSS 9.1
    SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability...
  • CVE-2026-28312CVSS 9.1
    SolarWinds Serv-U is affected by a privilege escalation vulnerability. This would elevate...
  • CVE-2026-28310CVSS 9.1
    SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a...
  • CVE-2026-28309CVSS 9.1
    SolarWinds Serv-U is affected by a broken access control vulnerability that allows...
  • CVE-2026-28308CVSS 9.1
    SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability...
Powered by CVE WATCHTOWER

Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Top Exploited CVEs
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • Disclaimer
    • DCMA
    • Privacy Policy
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • CVE Watchtower
    • CVE Statistics by Vendor 2026
    • Q2 2026 Report
    • Top Exploited CVEs
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.