Skip to main content
Emerging ThreatsMalware & Ransomware

WhatsApp Scam Exploits Linked Devices Feature to Hijack Accounts

Person sitting at home holding smartphone with WhatsApp conversation on screen.

“No Password, No Alert.”

Malwarebytes' August 3 research

On August 3, Malwarebytes published new research describing a WhatsApp scam that spreads through hijacked accounts by asking recipients to vote for a friend in an online contest and then tricking them into authorizing an attacker's device on their account. The company found examples in anonymized submissions to its scam‑checking tool. Messages arrived from contacts whose accounts were already compromised and referenced a ballet performance, a dog competition or a school event.

The "vote for a friend" lure and fake WhatsApp pages

The messages contained links that did not lead to voting pages. Instead, the links redirected victims to pages that resembled WhatsApp — often using the legitimate wa.me domain — and guided the victim through what looked like setting up WhatsApp Web. Other variants simply instructed the target to open their linked device settings and enter a code supplied by the scammer. In every case, the apparent voting pretext was a cover for a device‑linking flow.

Linked‑device hijack: how the attack works and why it can go unnoticed

The attackers were not trying to steal account passwords. Completing the flow added the attacker's device as a linked session, giving that device the same access a legitimate second device would have. That access includes reading messages, sending messages as the account holder and following conversations in real time. Attackers used those capabilities to forward the same scam to the victim's contacts and to ask friends and family for money.

Because no login occurred, there were no password reset emails or failed sign‑in alerts. The attacker's device appeared as another entry in the linked devices list. Malwarebytes warned that the compromise could go unnoticed for some time unless the user checked their linked devices.

GhostPairing, QR‑code lures and a reshaped pretext

Abuse of the linked devices feature is not new. Researchers documented the same mechanism in December 2025 under the name "GhostPairing," when attackers used fake photo‑viewer pages rather than voting requests. The report also notes that Russian state actors have used QR‑code and device‑linking lures against WhatsApp and Signal users in the past. What has changed in this campaign is the pretext: a low‑stakes, plausible request to help someone's child or pet win a contest, arriving from a real contact. Malwarebytes said that trust plus curiosity makes that combination effective.

What this means for end users, security teams, and contacts

  • End users: Malwarebytes advised people to review Settings then Linked devices and log out anything unfamiliar, never to scan a QR code or enter a linking code they did not initiate, and to verify unexpected requests through another channel. Anyone already affected should log out all linked devices and warn their contacts.
  • Security teams and technologists: The attack highlights a vector that does not generate traditional login alerts — no password resets, no failed sign‑in notifications — so monitoring for unauthorized linked sessions and unusual forwarding behavior is central to detection and containment.
  • Contacts and networks of compromised accounts: Because attackers forwarded the same scam from hijacked accounts and used those accounts to solicit money from friends and family, people receiving unusual requests even from known contacts should treat them with extra caution and confirm by alternate means.

The campaign is a reminder that the avenue of compromise is as important as the payload. By turning a familiar, low‑stakes social request into a device‑linking flow, attackers can inherit trust and remain silent on the usual audit channels. The only immediate technical record of such compromises, Malwarebytes' findings make clear, is the linked devices list — and the simple, often overlooked act of checking it.

Original story