GhostPairing — Campaign Analysis & Threat Activity

Threat entity extracted from intelligence sources

Frequency
6
occurrences
First Seen
December 17, 2025
Last Seen
February 6, 2026

GhostPairing is a threat campaign tracked across 5 threat clusters and 6 intelligence report mentions on ThreatCluster. First observed December 17, 2025; most recent activity February 6, 2026.

Overview

GhostPairing is a threat campaign that targets WhatsApp accounts by abusing the app’s device-linking feature to hijack sessions. The campaign leverages the device-link flow to gain unauthorized access to victims’ WhatsApp accounts, drawing official attention and highlighting weaknesses in cross-device authentication on popular messaging platforms.

Related Threat Clusters

  • WhatsApp Account Hijacking Exploits Device Linking Feature

    Threat actors are exploiting WhatsApp's device-linking feature to hijack accounts through a campaign named GhostPairing. This attack method does not require authentication, as victims are deceived into linking the…

    3 articles · Updated December 17, 2025
  • WhatsApp Accounts Compromised via Social Engineering and Malware

    Hackers have gained full access to WhatsApp accounts by using social engineering techniques to target phone numbers, bypassing the need for passwords or technical exploits. Additionally, a separate incident involved the…

    13 articles · Updated December 18, 2025
  • Ghostpairing: New WhatsApp Hijacking Threat via Social Engineering

    Ghostpairing is a newly identified cyber threat targeting WhatsApp users by exploiting the app's device-linking feature. This attack allows cybercriminals to hijack accounts without relying on stolen passwords or…

    2 articles · Updated December 30, 2025
  • Phishing Attacks via Signal Targeting German Officials and Journalists

    Germany's BfV and BSI have issued a warning regarding phishing attempts via the Signal messaging app. The attacks are believed to be conducted by state or state-controlled actors, targeting high-ranking officials in…

    12 articles · Updated February 6, 2026
  • CERT-In Alerts on WhatsApp 'GhostPairing' Vulnerability

    The Indian cyber security agency CERT-In has identified a vulnerability in WhatsApp's device-linking feature, termed 'GhostPairing'. This flaw allows attackers to gain complete control over user accounts, including…

    4 articles · Updated December 20, 2025

Recent Intelligence Reports

  • Germany warns of Signal account hijacking targeting senior figures — Bleepingcomputer · February 6, 2026
  • Ghostpairing: Stealthy WhatsApp Hijacking via Social Engineering — Webpronews · December 30, 2025
  • Indian cyber agency flags WhatsApp 'hijack' | India News — Hindustantimes · December 20, 2025
  • CERT-In Flags Vulnerability in WhatsApp Device-Linking Feature — Deccanchronicle · December 20, 2025
  • WhatsApp accounts targeted in ‘GhostPairing’ attack — Csoonline · December 18, 2025
  • WhatsApp device linking abused in account hijacking attacks — Bleepingcomputer · December 17, 2025

CVSS v3.1 Breakdown