GhostPairing Attack Campaign — Campaign Analysis & Threat Activity

Threat entity extracted from intelligence sources

Frequency
1
occurrences
First Seen
December 19, 2025
Last Seen
December 19, 2025

GhostPairing Attack Campaign is a threat operation that exploits the device-linking feature to hijack WhatsApp accounts.

Overview

GhostPairing Attack Campaign is a threat operation that exploits the device-linking feature to hijack WhatsApp accounts. Its hallmark is a device-linking exploit that lets attackers attach to existing WhatsApp sessions, enabling covert account takeover and potential data access across chats. The campaign is significant due to WhatsApp’s widespread use in personal and organizational communications and the stealthy risk of cross-device session compromise.

Related Threat Clusters

  • WhatsApp Accounts Compromised via Social Engineering and Malware

    Hackers have gained full access to WhatsApp accounts by using social engineering techniques to target phone numbers, bypassing the need for passwords or technical exploits. Additionally, a separate incident involved the…

    13 articles · Updated December 18, 2025

Recent Intelligence Reports

  • WhatsApp account takeovers enabled by device linking exploit — Scworld · December 19, 2025

Related Entities

CVSS v3.1 Breakdown