GhostPairing attack allows remote WhatsApp account linking
⚠️ Researchers at Gen Digital have identified a social-engineering technique dubbed GhostPairing that lets attackers add themselves as a trusted device to a victim’s WhatsApp account without passwords. By sending a malicious message that prompts the user to verify their phone number, attackers forward the generated pairing code and the user inadvertently approves the session. Once linked, the attacker can read and send messages in real time and propagate the scam to the victim’s contacts. Users should check Linked Devices and enable two-step verification.
