GhostPairing is a threat campaign tracked across 5 threat clusters and 6 intelligence report mentions on ThreatCluster. First observed December 17, 2025; most recent activity February 6, 2026.
GhostPairing is a threat campaign that targets WhatsApp accounts by abusing the app’s device-linking feature to hijack sessions. The campaign leverages the device-link flow to gain unauthorized access to victims’ WhatsApp accounts, drawing official attention and highlighting weaknesses in cross-device authentication on popular messaging platforms.
Threat actors are exploiting WhatsApp's device-linking feature to hijack accounts through a campaign named GhostPairing. This attack method does not require authentication, as victims are deceived into linking the…
Hackers have gained full access to WhatsApp accounts by using social engineering techniques to target phone numbers, bypassing the need for passwords or technical exploits. Additionally, a separate incident involved the…
Ghostpairing is a newly identified cyber threat targeting WhatsApp users by exploiting the app's device-linking feature. This attack allows cybercriminals to hijack accounts without relying on stolen passwords or…
Germany's BfV and BSI have issued a warning regarding phishing attempts via the Signal messaging app. The attacks are believed to be conducted by state or state-controlled actors, targeting high-ranking officials in…
The Indian cyber security agency CERT-In has identified a vulnerability in WhatsApp's device-linking feature, termed 'GhostPairing'. This flaw allows attackers to gain complete control over user accounts, including…