Warning to WhatsApp users : cybercriminals have discovered a disturbingly simple way to gain access to real-time conversations by manipulating the pairing or connection app's process . The attack, dubbed ' GhostPairing ' by researchers at Gen Digital (owner of Norton, Avast, Avira and AVG), does not require passwords or account details to execute and was recently detected in the Czech Republic.

All the attacker needs to do is convince a user to click on a malicious link sent to them as a WhatsApp message (to reveal a supposed Facebook photo). In the most common variation of the attack, a fake page appears asking the user to verify themselves by entering their mobile number.
See also: Hackers exploit delivery updates in WhatsApp and Signal
This number is then forwarded by the attackers to WhatsApp to initiate the 'device connection via phone number' feature, which adds new devices to an account. WhatsApp generates an 8-digit pairing code, which is intercepted and forwarded to the user. The user, who sees a new pairing prompt on WhatsApp, enters this code to confirm the pairing.
Unfortunately, this adds the attacker's browser session as a 'trusted device.' The game ends there: the attacker now has full access to the user's account, messages and message history, as well as the ability to view messages as they are sent and received.
“Once the device is connected, the attacker doesn’t need to exploit anything else. They have the same capabilities that any user has when they connect to WhatsApp Web on their own computer,” Gen Digital researchers said. “Everything happens within the confines of WhatsApp’s functionality.”
Even worse, attackers can alsosend messages impersonating the user to spread the campaign to the victim's WhatsApp contacts and groups.

GhostPairing: WhatsApp E2EE Bypass
GhostPairing is an example of an attack that exploits one of WhatsApp's biggest advantages: registering, connecting with other users, and adding up to four additional devices to an account is extremely convenient.
See also: Sturnus banking trojan steals messages from Signal & WhatsApp
It's one reason WhatsApp has become so popular. All users need to join is a phone number, with no need to remember a username or password. Another advantage is that the app relies on the encryption end-to-end, in which the private keys used to secure messages are stored on the device.
This should make it impossible to intercept private messages without physical access to the device or remote malware infection. GhostPairing shows that a social engineering attack can bypass this.
Interestingly, the attack is less practical when it asks users to pair via QR codes. This offers some relief for users of messaging like Signal, which only allows pairing requests via QR codes. However, the attack is still possible.

WhatsApp protection
Users can check which devices are “paired” through WhatsApp by going to Settings > Connected Devices. A malicious device link will appear here. Despite having access to the user’s WhatsApp account, the attacker cannot revoke device their, which must be initiated from the primary device.
Another tip is to enable two-step verification with a PIN. This won't stop the attacker from accessing your messages, but they won't be able to change your primary email address.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Python-based WhatsApp worm spreads Eternidade Stealer
The threat to businesses is that a large number of employees use WhatsApp. The recommendation is to assume that there are multiple chat groups and educate users to report suspicious attempts or spam
The message should be clear: messaging on WhatsApp may seem private, but the app itself has loopholes that attackers can exploit.
GhostPairing comes just weeks after university researchers discovered a serious bug in WhatsApp that allowed them to discover the mobile numbers of the app's global user base of 3.5 billion.
