Skip to content
June 28, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Watchtower
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Vulnerability Report
Light/Dark Button
  • Home
  • News
  • Cybercriminals
  • GhostPairing: New Attack Hijacks WhatsApp via Linked Devices, Tricking Users with Fake Facebook QR Code
  • Cybercriminals

GhostPairing: New Attack Hijacks WhatsApp via Linked Devices, Tricking Users with Fake Facebook QR Code

Do Son December 17, 2025 3 minutes read
0
WhatsApp antitrust API probe India SIM-Binding Mandate Messaging App KYC WhatsApp DMA Interoperability BirdyChat Haiket Denmark Social Media Ban CVE-2025-55177 WhatsApp vulnerability, zero-click flaw npm Malware, System Wipe WhatsApp Windows App, WebView2 Downgrade WhatsApp Ban, US House NSO WhatsApp, Pegasus Spyware WhatsApp iPad iPadOS app
Add as a preferred
source on Google

A deceptive new cyberattack campaign is turning one of WhatsApp’s most convenient features into a weapon, allowing hackers to take full control of user accounts without ever stealing a password or touching a SIM card. Dubbed “GhostPairing” by researchers at Gen Digital, the attack relies not on sophisticated code exploits, but on a clever manipulation of user trust and the “linked devices” function found in modern messaging apps.

The attack typically begins with a message from a compromised contact, utilizing a hook that is almost impossible for many to ignore. The victim receives a text saying something innocuous like, “Hey, I just found your photo!” accompanied by a link that generates a legitimate-looking preview, often imitating a Facebook post.

“The message includes a link that appears as a Facebook style preview. When users open it, they see a page that imitates a Facebook viewer and asks them to ‘verify’ before they can see the content”.

This “verification” step is the trap. The page guides the user through a quick sequence of actions—steps that seem like standard security checks but are actually authorizing a hostile takeover.

WhatsApp GhostPairing, Linked Device Hijack
Lure message received by the victim | Image: Gen Digital

Unlike traditional attacks that try to harvest login credentials, GhostPairing tricks the victim into essentially handing over the keys to the castle. The attackers use the verification process to initiate WhatsApp’s own device pairing flow.

By prompting the user to scan a QR code or enter a numeric code under the guise of verifying their identity, the victim unwittingly links the attacker’s browser to their WhatsApp account.

“There is no password theft or SIM swap – instead, the user approves the attacker themselves by entering a pairing code that looks like normal verification”.

Once the link is established, the attacker has a persistent, invisible window into the victim’s digital life. They can send messages, read private conversations, and spread the malware further—all while the legitimate owner continues to use their phone, oblivious to the “ghost” device running in the background.

The genius—and danger—of the GhostPairing attack lies in its simplicity. It does not attempt to break encryption or bypass two-factor authentication in the traditional sense. Instead, it exploits the intended design of the software.

“The campaign described here illustrates a subtle shift in how some attackers operate. Instead of breaking cryptography or circumventing authentication, they use the product as designed and persuade users to cooperate at just the right moment”.

Gen Digital researchers warn that this technique represents a broader threat to the digital ecosystem, as many platforms now prioritize seamless multi-device connectivity. “The design pattern that made GhostPairing possible is not unique to WhatsApp. Any platform that combines very easy pairing with low visibility of linked devices gives attackers something to work with”.

The campaign was first detected in Czechia but has the potential to spread globally due to its language-agnostic methodology. The incident serves as a stark reminder that in an era of convenient connectivity, a single moment of inattention can have lasting consequences.

“GhostPairing should be read as a warning, not just a WhatsApp incident. The more our digital lives depend on quick QR scans and ‘approve on your phone’ flows, the more important it becomes to design these steps so that a single moment of inattention does not quietly create a ghost device that lives in the background for months”.

Related Posts:

  • QR Codes Coming to Linux Kernel Panics with 6.12 Release
  • The Hidden Danger of PDF Files with Embedded QR Codes, Researchers Warn
  • QR Code Phishing Attacks Escalate: Sophisticated Campaign Targets Chinese Citizens
  • “Unicode QR Code Phishing”: The New Threat You Need to Know

Related coverage

  • Power Parasites: Scam Campaign Targets Global Energy Brands
  • Beast Ransomware Emerges as New RaaS Threat, Using ChaCha20 and Stealthy VSS Deletion
  • International Takedown Smashes Massive Crypto Laundering Service
  • Legitimate Remote Tools Weaponized in Sophisticated Spam Campaign
  • CISA Warns of Unsophisticated Cyber Actors Targeting U.S. Critical Infrastructure OT Systems

Support Our Threat Intelligence

If you find our CVE report and cybersecurity news helpful, consider supporting our work.

Buy Me a Coffee Logo Buy Me a Coffee PayPal
Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Share this article:

Facebook Post LinkedIn Telegram
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: Account Hijack Gen Digital GhostPairing Linked Devices phishing QR Code Scam User Trust WhatsApp

Leave a Reply Cancel reply

You must be logged in to post a comment.

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🚨 Active Exploits in the Wild

  • CVE-2026-42208
    LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version...
  • CVE-2018-1273CVSS 9.8
    Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a...
  • CVE-2026-20230CVSS 8.6
    A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified...
  • CVE-2026-12569
    A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The...
  • CVE-2026-28496CVSS 9.4
    FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 have a Server-Side Template...
  • CVE-2026-21509CVSS 7.8
    Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a...
  • CVE-2026-34908CVSS 10.0
    A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi...
  • CVE-2026-34909CVSS 10.0
    A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS...
  • CVE-2026-34910CVSS 10.0
    A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi...
  • CVE-2025-67038CVSS 9.8
    An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write...
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-12415CVSS 9.8
    The Invoice Generator plugin for WordPress is vulnerable to privilege escalation due...
  • CVE-2026-28701CVSS 9.8
    Various versions of Daktronics Controller Firmware could allow authenticated and unauthenticated remote...
  • CVE-2026-53576CVSS 10.0
    Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21,...
  • CVE-2026-49869CVSS 10.0
    Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21,...
  • CVE-2026-54350CVSS 10.0
    Budibase is an open-source low-code platform. Prior to 3.39.12, an unauthenticated visitor...
  • CVE-2026-54352CVSS 9.6
    Budibase is an open-source low-code platform. Prior to 3.39.9, `POST /api/pwa/process-zip` at...
  • CVE-2026-52785CVSS 9.9
    OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1,...
  • CVE-2026-52782CVSS 9.9
    OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1,...
  • CVE-2026-52780CVSS 9.6
    OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1,...
  • CVE-2026-46386CVSS 9.9
    OpenProject is open-source, web-based project management software. Prior to , the official...
Powered by CVE WATCHTOWER

Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • Disclaimer
    • Privacy Policy
    • DMCA NOTICE
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.