Listen to this Post
Introduction: When a Familiar Message Becomes a Digital Trap
Cybercriminals are constantly searching for the weakest point in digital security, and increasingly, that weakness is not technology itself — it is human trust. A new WhatsApp scam campaign demonstrates how attackers can transform ordinary conversations between friends, family members, and colleagues into powerful tools for account takeover.
Unlike traditional phishing attacks that attempt to steal passwords, this campaign uses a more subtle method: convincing victims to authorize an attacker-controlled device through WhatsApp’s legitimate linked-device feature. The victim does not lose their password, does not receive a suspicious login warning, and may not even realize anything happened.
According to research from Malwarebytes published on August 3, attackers are hijacking WhatsApp accounts and using those compromised accounts to send convincing messages asking contacts to vote for someone in a fake online contest. The requests appear harmless — supporting a child’s performance, helping a pet win a competition, or voting in a school event — but the real goal is to gain control of another WhatsApp account.
This attack highlights a dangerous evolution in social engineering: criminals are no longer pretending to be strangers. They are becoming trusted people inside existing conversations.
The Scam Begins With a Message From Someone You Know
The campaign starts with a WhatsApp message that appears to come from a friend, colleague, or family member. However, the sender’s account has already been compromised.
The message usually contains an emotional request:
“Can you vote for my daughter in this competition?”
“Please help my dog win this contest.”
“Can you support my school event?”
These scenarios are carefully chosen because they feel natural. They do not create fear or urgency like traditional scams. Instead, they encourage kindness and curiosity.
Malwarebytes discovered the campaign through anonymized submissions to its scam-checking tool. Researchers observed that the messages came from previously hijacked accounts, allowing attackers to exploit existing trust networks.
The victim sees a familiar profile picture, a known name, and a normal conversation history. This creates a false sense of security.
The Fake Voting Page That Steals Control Without Stealing Passwords
One of the most dangerous aspects of this attack is that it does not rely on traditional credential theft.
The link sent in the message does not lead to a legitimate voting page. Instead, it redirects victims to a fake website designed to imitate WhatsApp.
In some versions of the scam, attackers use the legitimate WhatsApp short-link domain format, such as wa.me, to make the process appear more trustworthy.
The fake page guides users through what looks like a WhatsApp Web setup process.
The victim may be asked to:
Scan a QR code.
Enter a device-linking code.
Open WhatsApp settings and approve a new device.
The user believes they are helping someone vote.
In reality, they are granting an attacker access to their WhatsApp account.
The Silent Account Takeover: No Password Required
Traditional account attacks usually involve stealing passwords, bypassing authentication, or triggering suspicious login alerts.
This campaign works differently.
The attacker does not need:
Your password.
Your SMS verification code.
Your email account.
Your existing phone.
Instead, the attacker abuses WhatsApp’s linked-device functionality.
When the victim approves the connection, the attacker’s device becomes a legitimate linked session. From WhatsApp’s perspective, the action appears similar to a user connecting WhatsApp Web on their own computer.
This makes the attack extremely dangerous.
There may be:
No password reset notification.
No failed login warning.
No suspicious sign-in alert.
The attacker simply appears inside the account’s linked devices list.
What Attackers Can Do After Taking Control
Once attackers gain access, they can operate almost like the real account owner.
They may:
Read private conversations.
Monitor incoming messages.
Send messages to friends and family.
Impersonate the victim.
Request money from contacts.
Spread the same scam campaign further.
The compromised account becomes a new distribution channel.
This creates a chain reaction:
One person’s WhatsApp account is compromised.
Attackers use it to message hundreds of contacts.
Those contacts trust the sender.
More accounts become infected.
The attack grows through social relationships rather than technical vulnerabilities.
Why This Scam Is More Effective Than Normal Phishing
The success of this campaign comes from psychological manipulation.
Traditional phishing often depends on creating panic:
“Your account will be deleted.”
“Your payment failed.”
“Your password was compromised.”
This campaign uses a completely different emotion: cooperation.
The attacker creates a situation where helping someone feels like the right thing to do.
A request involving a child, pet, or community event feels personal. Victims are less likely to question a message from someone they already know.
The attacker does not need to break WhatsApp security.
They simply convince the user to open the door themselves.
A Growing Pattern: Device Linking Attacks Are Becoming Popular
The technique behind this campaign is not completely new.
Security researchers previously documented similar attacks, including campaigns known as GhostPairing, where attackers used fake photo-viewing websites to trick users into linking malicious devices.
State-sponsored groups have also used QR-code and device-linking methods against messaging platforms such as WhatsApp and Signal.
The technology itself is legitimate.
WhatsApp’s linked-device feature exists to make it easier for users to access their accounts from computers and additional devices.
The problem is that attackers are abusing a trusted feature through deception.
Deep Analysis: Understanding WhatsApp Linked Device Abuse
How the Attack Flow Works
A simplified attack chain looks like this:
Victim receives WhatsApp message
|
v
Message contains fake contest link
|
v
Victim opens fake WhatsApp page
|
v
Victim approves device linking request
|
v
Attacker device becomes authorized
|
v
Account takeover begins
|
v
Scam spreads to victim contacts
Security Investigation Commands
Users and administrators can perform basic security checks.
Check active WhatsApp sessions:
WhatsApp Settings
|
v
Linked Devices
|
v
Review active sessions
Remove unknown devices immediately.
Android security review:
Settings > Apps > WhatsApp > Permissions
Check whether unusual permissions were granted.
Device monitoring:
Android users can review recent activity:
Settings > Security > Device Activity
iPhone users can check:
Settings > Apple ID > Devices
for unfamiliar devices.
Enterprise Protection Recommendations
Organizations using WhatsApp for business communication should consider:
1. Employee security awareness training
2. Mandatory MFA education
3. Verification procedures for financial requests
4. Regular linked-device reviews
5. Incident reporting procedures
How Users Can Protect Their WhatsApp Accounts
Never Approve Unknown Device Links
A simple rule can prevent many attacks:
If you did not personally start the WhatsApp Web connection, do not approve it.
Never:
Scan unknown QR codes.
Enter device-linking codes provided by others.
Follow “vote” links asking for WhatsApp authorization.
Regularly Check Linked Devices
Users should periodically inspect connected devices.
Open:
→ Settings
→ Linked Devices
Remove anything unfamiliar.
This is one of the easiest ways to detect silent account compromise.
Verify Suspicious Requests Through Another Channel
If a friend suddenly asks for:
A contest vote.
Money.
Personal information.
A verification code.
Contact them separately.
Call them.
Send an SMS.
Ask directly.
A compromised WhatsApp account can perfectly imitate the communication style of the real owner.
What To Do If Your Account Is Already Compromised
Victims should act quickly.
Recommended steps:
Step 1: Remove Unauthorized Devices
Go to:
WhatsApp Settings
→ Linked Devices
→ Log out all unknown sessions
Step 2: Warn Your Contacts
Tell friends and family that previous messages may have been sent by attackers.
This prevents further victims.
Step 3: Enable Strong Account Protection
Activate:
WhatsApp Settings
→ Account
→ Two-step verification
Create a PIN that attackers cannot guess.
What Undercode Say:
Trust Has Become the New Attack Surface
The latest WhatsApp campaign proves that cybersecurity is no longer only about protecting systems. It is about protecting decisions made by humans.
Attackers Are Moving Beyond Password Theft
Password stealing is becoming less attractive because modern platforms have stronger authentication protections.
Device authorization attacks are more effective because victims unknowingly approve access themselves.
Social Engineering Is Becoming More Advanced
The attackers behind this campaign understand human behavior.
They know people are more likely to respond positively when they believe they are helping someone they know.
Familiar Contacts Create False Security
A message from a stranger creates suspicion.
A message from a friend creates trust.
Attackers are exploiting this psychological difference.
Legitimate Features Are Becoming Attack Tools
The WhatsApp linked-device feature is not vulnerable by design.
The problem is that attackers are manipulating users into using legitimate security functions against themselves.
AI Could Make These Attacks Worse
Future versions of these scams could use artificial intelligence to:
Copy writing styles.
Generate personalized messages.
Analyze conversations.
Impersonate users more accurately.
Account Hijacking Is Becoming More Valuable
A stolen WhatsApp account provides access to an entire social network.
Attackers do not only steal one account.
They use one account to reach hundreds of additional victims.
Users Need Security Habits, Not Just Security Tools
No security system can fully protect users who voluntarily approve malicious actions.
Awareness remains one of the strongest defenses.
Messaging Platforms Need Better Warnings
Platforms should improve warnings around device linking.
For example:
“Are you sure you want to connect this device? Did someone ask you to do this?”
Simple friction could stop thousands of attacks.
The Future Battle Will Be Against Manipulation
Cybersecurity is moving from technical exploitation toward psychological exploitation.
The strongest defense will combine technology, education, and cautious digital behavior.
✅ Confirmed: WhatsApp Linked Device Abuse Is a Real Attack Method
Security researchers have documented multiple campaigns where attackers abuse device-linking features instead of stealing passwords.
The method allows attackers to maintain access through authorized sessions.
✅ Confirmed: Malwarebytes Reported the Contest Voting Scam Campaign
The campaign described by Malwarebytes involved fake voting requests sent from previously compromised WhatsApp accounts.
The objective was account takeover through device linking.
✅ Confirmed: Users Can Detect Compromise Through Linked Devices
Checking WhatsApp linked sessions is one of the recommended methods for identifying unauthorized access.
Removing unknown devices immediately reduces attacker control.
❌ False Belief: Password Changes Alone Always Fix WhatsApp Hijacking
Changing a password may not remove already authorized linked devices.
Attackers can maintain access until those sessions are manually removed.
Prediction
(+1) Positive Prediction: Messaging Platforms Will Introduce Stronger Anti-Linking Protection
As device-linking scams become more common, WhatsApp and similar platforms are likely to introduce stronger confirmation systems.
Future protections may include:
More visible security warnings.
Location-based alerts.
AI-powered scam detection.
Automatic blocking of suspicious linking attempts.
(-1) Negative Prediction: AI Will Make Social Engineering Attacks More Convincing
Cybercriminals will likely use AI tools to create more personalized scams.
Instead of generic contest messages, attackers may generate realistic conversations based on previous chats, making detection significantly harder.
The future of messaging security will depend not only on stronger encryption but also on stronger human awareness.
▶️ Related Video (80% Match):
🕵️📝Let’s dive deep and fact‑check.
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
References:
Reported By: www.infosecurity-magazine.com
Extra Source Hub (Possible Sources for article):
https://www.stackexchange.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube




