A newly identified cyber campaign, dubbed the GhostPairing Attack, allows cybercriminals to take complete control of WhatsApp accounts without passwords, SIM swaps, or malware.
Researchers revealed that attackers exploit WhatsApp’s legitimate device linking feature to register their own browser as a trusted device silently.
Once paired, the attacker gains direct, ongoing access to the victim’s private chats, shared media, and contacts, thereby creating an invisible “ghost” session that mirrors the account.
How the Attack Operates
The campaign typically starts with social engineering. Victims receive a brief message from one of their contacts, normally stating “Hey, I just found your photo!” and accompanied by a link displaying a Facebook-style preview.
When the link is opened, it redirects to a fake Facebook viewer page that asks the user to verify their identity before viewing the content.

This page is not connected to Facebook but serves as the attacker’s control interface, linking the victim directly to WhatsApp’s official device pairing system.
When the user enters their phone number into the page, the attacker’s server forwards it to WhatsApp’s legitimate “link device via phone number” feature. WhatsApp then generates a numeric pairing code intended only for the account owner.
The malicious page displays the same code and includes a prompt asking the user to enter it in their WhatsApp app to “verify the login.” Once the code is confirmed, WhatsApp treats the attacker’s browser as an approved linked device.
The victim’s account continues to function normally, making the compromise almost invisible. Attackers can now read old messages, receive new ones in real time, access media files, and even send messages to others as if they were the victim.
Global Threat and Mitigation
Initial activity was observed in Czechia, where compromised accounts sent messages in local languages to contacts in neighboring countries.
The malicious links were hosted on lookalike domains such as photobox[.]life, yourphoto[.]world, and photopost[.]live.
The repeated use of identical layouts and naming conventions indicates that the GhostPairing toolkit operates as a reusable kit sold or shared among attackers.
Unlike traditional account-hijacking methods, GhostPairing does not rely on stealing credentials or breaking encryption; it exploits normal user behavior through trust and familiarity.
The attacker remains hidden until the victim reviews their list of linked devices. Security experts urge users to open WhatsApp settings, check the Linked Devices section, and immediately remove any unknown sessions.
Awareness is considered the most effective defense, as the attack exploits convenience rather than code vulnerabilities, turning a legitimate feature into a persistent surveillance channel.
Find this Story Interesting! Follow us on Google News , LinkedIn and X to Get More Instant Updates