A new campaign ‘hacks’ WhatsApp accounts without stealing passwords or duplicating the SIM

A new campaign manages to get hold of it control of WhatsApp accounts through an attack called ‘GhostPairing’, in which the user himself makes the fraudulent link with a browser controlled by the cybercriminal.

‘GhostPairing’ begins with a message that the victim receives from one of their contacts. In it he informs you that he has found a photograph in which it appears and shares a link so you can check it out.

This link opens a login page that imitates that of Facebook, in which you are asked to enter your phone number and then asked to scan a QR code with the WhatsApp application or enter a numerical code to confirm registration, the latter method being much more common.

What these steps do is guide the victim through the device pairing process of the messaging application that, legitimately, allows you to join the main account on up to four devices and access it without having to use the main smartphone.

Precisely, linking by telephone number is available to the customer of WhatsApp for Windows or WhatsApp Web. In this campaign, a cybercriminal abuses this legitimate tool to take control of the user’s account in the browser.

In this way, the cybercriminal can open WhatsApp Web in his browser, although in the eyes of WhatsApp itself it was the victim who linked a new device, although he did not realize it. Hence the name of the attack, ‘GhostPairing’ or phantom pairing, as the Gen Digital researchers explain.

By having access to the account, the cybercriminal accesses the same functions that any user can have on WhatsApp Web: conversation history, receiving messages in real time, downloading documents and multimedia filesetc.

You can also send messagestaking advantage of the victim’s contact list. This is how the cybercriminal initially contacted the victim with the message in the photograph. All this without stealing access credentials or making a fraudulent duplicate of the SIM card.

By Editor

One thought on “A new campaign ‘hacks’ WhatsApp accounts without stealing passwords or duplicating the SIM”
  1. https://www.displaybestellen.nl/gra-z-ptitseyu-kros%d1%96/
    https://dentpalace.com/baromfiut-okozta-kozuti-baleset-online-jatek-tegyel-meg-valodi-penzes-nyerogepen-98-os-rtp-vel/
    https://bioquinor.com/chicken-road-artificio-da-bisca-gioca-al-incontro-del-pollo-in-italia/
    https://pspsports.co.uk/play-stone-household-bonanza-slot-demonstration-by-the-practical-gamble/
    https://vegedalle.com/top-10-ofertas-criancice-bonus-acercade-casinos-online-2025/
    https://master123.org/fantastic-nugget-helyi-kaszino-hozzaszolas-van-promocios-jelszavad/
    https://abicmguinee.com/2025/12/07/a-legjobb-online-blackjack-kaszinok-2025-ben-a-legjobb-blackjack-weboldalak/
    http://www.555jixiang.com/sports-news/5859.html
    https://doyan88.org/naykrashch%d1%96-onlayn-kazino-nyu-yorka-spisok-desyati-naykrashchikh-u-2025-rots%d1%96/
    http://www.tomei-acne.com/v%d1%96taln%d1%96-bonusi-spoluchen%d1%96-shtati-ameriki-2025-krashch%d1%96-propozits%d1%96%d1%97-signal-up-now-v-onlayn-kazino/
    https://csnakliyat.com/avtoritetniy-veb-sayt-v%d1%96deo%d1%96gor/
    http://www.deniziskele.com/azartna-gra-na-ptitsyu-k%d1%96lka-chutt%d1%94vikh-kh%d1%96t%d1%96v-%e2%80%8b%e2%80%8b12-kazino-v-yakikh-mozhna-grati/
    http://test.pawprintsid.com/wordpress/2025/12/08/online-kaszino-elemzes-es-pontszam/
    https://pizzarebels.de/naykrashch%d1%96-ta-velik%d1%96-viplati-dlya-vs%d1%96kh-nas-u-kazino-2025-roku-bezpechn%d1%96sh%d1%96-ta-prov%d1%96dn%d1%96sh%d1%96/
    https://chaugiaphat.com/2025/12/07/naykrashch%d1%96-onlayn-%d1%96gri-kazino-na-realn%d1%96-grosh%d1%96-u-2025-rots%d1%96/
    https://bulan69slot.com/naykrashch%d1%96-dodatkov%d1%96-kodi-kazino-2025-naykrashch%d1%96-kuponi/
    https://cberglobal.com/lieve-online-casinos-2025-ksa-vergunning/
    https://bosku365.com/alle-legale-offlin-casinos-wegens-holland-2025/
    https://shclinic.pl/2025/12/11/10-naykrashchikh-mob%d1%96lnikh-kazino-%d1%96-vi-mozhete-zaprogramuvati-realnu-valyutnu-gru-2025-roku/
    https://teatrskazka.info/?p=6104
    https://www.cashforcaravans.com.au/10-best-live-casinos-to-play-the-real-deal-money-online-in-the-2025/
    https://ar-te.org/2025/12/100-okrem%d1%96-ta-naykrashch%d1%96-rekomendats%d1%96%d1%97-onlayn-kazino-2025-roku/
    https://powellandparrish.com/gralniy-tsentr-chicken-street-bezkoshtovn%d1%96-azartn%d1%96-%d1%96gri-na-realn%d1%96-grosh%d1%96/
    https://bibirslot.com/10-legjobb-valodi-penzes-kaszino-az-interneten-ahol-amerikai-jatekosokat-szerezhetsz-2025-ben/
    https://bunyi123.com/eersterangs-online-bank-holland-2025-lieve-legale-casinos/

Leave a Reply