GhostPairing Latest News
Recently, the Indian Computer Emergency Response Team (CERT-In) has issued an advisory about an active threat campaign which targets WhatsApp users by using a new technique called GhostPairing.
About GhostPairing
- GhostPairing is a type of WhatsApp attack where hackers secretly link their own device to a victim’s WhatsApp account.
- It gives hackers almost full access without the victim noticing.
- GhostPairing' allows cybercriminals to take complete control of WhatsApp accounts without requiring passwords or SIM swaps.
- The threat actors can take over WhatsApp accounts without authorisation by tricking potential victims into entering the pairing codes.
Modus Operandi of GhostPairing
- GhostPairing begins with victims receiving a message from a trusted contact that reads: “Hi, check this photo”.
- The message contains a link with a Facebook-style preview.
The link leads to a fake Facebook viewer that prompts users to “verify” to see the content.
Then, the attackers attempt to trick potential victims into entering their phone number and code. - By following a sequence of steps, victims unknowingly grant attackers full access to their WhatsApp accounts.
Source: IE
GhostPairing FAQs
Q1: What is the primary method used in the GhostPairing scam?
Ans: Exploiting WhatsApp's device-linking feature
Q2: How does the GhostPairing scam typically start?
Ans: Attackers send messages with links from "trusted contacts"