- By Prateek Levi
- Fri, 26 Dec 2025 10:12 PM (IST)
- Source:JND
WhatsApp GhostPairing: What is troubling about GhostPairing is its quick popularity among scammers targeting WhatsApp users, and this is not because of system crash assaults or password phishing, but rather because of how victims willingly allow attackers to access their very own account. Unlike most phishing assaults involving OTP-stealing or SIM cards, this type of attack relies on pure phishing and relies on WhatsApp's device connection process.
The Government of India has now finally given an official warning for this particular threat. It is after the Indian Computer Emergency Response Team (CERT-In) indicated that hackers have been using the pairing code for the silent addition of their browsers as trusted devices for the victim’s WhatsApp account.
GhostPairing Attacks Use Device Linking
CERT-In reports that malicious actors are exploiting WhatsApp’s device-linking feature, where pairing the device does not necessarily demand an authentication layer. Since there is a flaw in the system, hackers use it and manage access to an account without OTP verification, passwords, or even a SIM swap. The moment their device gets paired, they continue enjoying their chats and messages.
How Victims Are Being Tricked
The advisory states that ‘the scam typically starts with a legitimate-looking message saying something like “Hi, check this photo.” It may be from someone you actually recognise and come with a preview that looks very much like it’s going to be a link to something on social media, according to Rosenbach.
When the link is clicked and opened, User is directed to another page requiring him to confirm his identity before he is able to check out the photo. Behind this notification, another feature on "WhatsApp: Link a device via phone number" is silently activated.
Where The Account Takeover Takes Place
At this point, a majority of users will unknowingly grant approval for the request, which they think is a process of viewing. Upon approval, the attacker's browser is considered a trusted device. From there on, the user account is completely under the hacker's control, and it might take some time for the user to realise it.
There is no OTP input. There is no password that is breached. It is the user’s device that approves.
ALSO READ: Will Apple Make iPhone 18 Camera Sensors In The US For The First Time? This Is What Reports Suggest
Why GhostPairing Feels Convincing
The scam is able to spread so quickly because it uses a combination of trust, familiarity, and a normal WhatsApp service. There are no warnings or security notifications when the scam takes place. The process just looks like the normal course.
