Bleepingcomputer
WhatsApp Account Hijacking Exploits Device Linking Feature
First seen 17 Dec 2025, 20:55 UTC
•

•67% similarity
•55.9
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
Threat actors are exploiting WhatsApp's device-linking feature to hijack accounts through a campaign named GhostPairing. This attack method does not require authentication, as victims are deceived into linking the attackers' browser to their WhatsApp account. The campaign was initially identified in Czechia but is capable of spreading to other regions.
ThreatCluster AI