Growing Threat: WhatsApp Scam Utilizing Hijacked Accounts
A new scam targeting WhatsApp users is making the rounds, exploiting compromised accounts to trick recipients into voting for a friend in an online contest. The ruse ultimately leads them to authorize the attacker’s device, granting the scammer access to the victim’s account. This alarming development has come to light through a research study conducted by Malwarebytes, published on August 3, that outlines the mechanics of this insidious scheme.
Malwarebytes’ research reveals intriguing details about the deceptive messages, which are sent from contacts whose accounts have already been hijacked. The scammers craft messages that reference engaging events such as ballet performances, dog shows, or school contests, creating a façade that makes the request appear legitimate. This clever manipulation plays into the victim’s curiosity and trust, making them more likely to comply.
The critical point in this scam lies in the link provided in these messages. Contrary to what one might expect, the link does not redirect users to a voting site. Instead, it leads to a webpage designed to mimic WhatsApp, often utilizing the legitimate wa.me domain. Victims are misled into believing they are setting up WhatsApp Web, entering a pathway that ultimately compromises their accounts. In some instances, victims are directed to access their device settings and input a code supplied by the scammer, further solidifying the deceitful nature of the operation.
One of the most troubling aspects of this scam is that the attackers are not seeking traditional login credentials. Instead, by completing the deceptive flow, the scammer adds their device as a linked session to the victim’s account. This tactic enables the false user to read messages, dispatch texts as the account holder, and follow ongoing conversations in real time. Consequently, the attackers can disseminate the same scam to the victim’s contacts and solicit money from friends and family, all while maintaining an air of authenticity.
A significant security risk posed by this method is the lack of typical warning signs associated with account breaches. Since no login is involved, victims do not receive any password reset emails or failed sign-in alerts. The scammer’s device simply appears as another entry in the linked devices list associated with the victim’s account. Malwarebytes emphasizes the stealthy nature of this compromise; unless users routinely check their linked devices, they might remain unaware of the breach for an extended period.
This method of exploiting the linked devices feature is not entirely new. Researchers had previously documented a similar technique back in December 2025, referring to it as GhostPairing. In that instance, scammers utilized fake photo-viewing pages as bait rather than voting requests. The current campaign underscores a worrying trend, as Russian state actors have also employed QR code and device-linking tactics against WhatsApp and Signal users.
The evolution of this scam’s pretext is, perhaps, one of its most insidious aspects. Making a request to support a friend’s child or pet in a contest feels low-risk and plausible, particularly when it originates from someone within the victim’s circle. This combination of trust and curiosity is a potent recipe for manipulation, making victims more susceptible to falling for the ploy.
In light of these developments, Malwarebytes offers crucial advice for users to safeguard their accounts. It is imperative for individuals to routinely navigate to their Settings and review the Linked Devices section, logging out of any unfamiliar entries. Moreover, they should never scan QR codes or input linking codes not initiated by themselves. To further enhance security, it is advisable to verify any unexpected requests through alternative communication channels.
For those who may already have been affected by this scam, Malwarebytes strongly recommends logging out of all linked devices immediately and notifying their contacts about the compromise. As this scheme continues to evolve, vigilance and awareness are more critical than ever in protecting personal information and maintaining account security in an increasingly connected world.

