HomeinetNew WhatsApp scam gains access to your conversations

New WhatsApp scam gains access to your conversations

A new WhatsApp scam has begun circulating on the messaging platform, exploiting the popular device linking feature to gain complete control of users' accounts.

See also: WhatsApp Status tests Close Friends feature

WhatsApp

The attack begins when recipients receive a seemingly innocent message from a known contact, which typically states “Hi, I accidentally found your photo!” accompanied by a shortened URL link. Once clicked, the link redirects victims to a fake Facebook login portal, precisely designed to resemble the legitimate interface and collect credentials.

Initial reports indicate that the scam first appeared in Central Europe before quickly spreading to multiple regions, using social engineering techniques to appear authentic. By entering their credentials on the fake page, victims unwittingly grant the attackers access to WhatsApp’s login mechanism. The malware then connects to WhatsApp desktop and web sessions, generating a valid QR code link using the compromised session credentials. Within minutes, malicious actors can view and extract chat histories, media files, and contact lists. Financial fraud, identity theft, and further targeted attacks are likely to follow once control is fully established.

Gen Threat Labs analysts discovered the malware after correlating unusual authentication requests with reports of unauthorized logins to WhatsApp Business accounts. Their research revealed that the backend infrastructure of the scam uses invisible sets of servers to transmit session credentials, avoiding detection by conventional network monitoring tools. The attackers also use ephemeral subdomains, which rotate almost hourly to thwart takedown attempts and evade IP-based blacklisting.

See also: WhatsApp urgent update for iOS and macOS apps

New WhatsApp scam gains access to your conversations

In addition to collecting credentials and hijacking sessions, the scam incorporates subtle persistence features. A lightweight JavaScript payload injected into the fake page entices unsuspecting users to install a browser extension that supposedly “enhances privacy.” In reality, this extension works in the background, refreshing the stolen session credentials and occasionally prompting users to reauthenticate, thus maintaining continuous access. If users attempt to revoke permissions on Facebook, the malicious script intercepts the revocation flow and displays a misleading error message, further trapping victims in a loop.

The infection mechanism relies on a classic credential phishing strategy enhanced by the reuse of session credentials. Once a user submits login details to the fake page, the server component immediately creates a headless WhatsApp Web session using Puppeteer automation. This headless session generates a valid QR code that is forwarded to the attacker’s console, effectively linking the victim’s mobile account to the attacker’s instance without any notification to the user.

To maximize invisibility, attackers limit automation scripts to mimic human browsing habits, with random mouse movements and keystroke delays. This approach bypasses heuristics that flag rapid, repeated login attempts, allowing malicious actors to remain under the radar.

WhatsApp is one of the most popular messaging apps in the world, with billions of users worldwide. It was created in 2009 by Jan Koum and Brian Actonand was acquired by Facebook (now Meta) in 2014. The app allows users to send text messages, photos, videos, voice messages, and make voice and video calls over the internet (Wi-Fi or mobile data).

See also: WhatsApp adds new fraud protection features

New WhatsApp scam gains access to your conversations

One of WhatsApp's key features is end-to-end encryption, which ensures that only the sender and recipient can read the contents of messages. This makes it particularly attractive to users who value privacy and security.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS