WhatsApp Account Takeover Scam Abuses 'Linked Devices' Feature
A social engineering scam is tricking WhatsApp users into authorizing malicious device linking, granting attackers access to their accounts and conversations.

A widespread scam circulating on WhatsApp is leveraging social engineering tactics to achieve full account takeover by tricking users into authorizing malicious device linking. The attack begins with a seemingly innocuous message, often from a compromised contact, requesting the victim's help to vote for a friend in an online contest. These contests can range from ballet performances to pet shows, employing casual and sometimes urgent language to prompt a quick click.
While the message appears harmless, the provided link does not lead to a legitimate voting page. Instead, it redirects users to a deceptive page, sometimes utilizing the legitimate WhatsApp domain wa.me, where the actual exploit unfolds. This scam capitalizes on the trust users place in their contacts and their natural curiosity, making them less likely to question the request and more inclined to assist.
In many instances, the scam directs victims through a process that mimics the legitimate WhatsApp 'Linked devices' feature. Users are guided through steps that appear to be setting up WhatsApp Web or linking a new device. The ultimate goal is to trick the user into authorizing a new linked session, which grants the attacker unfettered access to their WhatsApp account.
Once an attacker successfully links their device, they gain the same capabilities as a legitimate linked device. This includes the ability to read messages, send messages impersonating the victim, and access ongoing conversations in near real-time. The attacker's device simply appears as another linked session on the victim's account, making the compromise difficult to detect without actively checking the 'Linked devices' settings.
This method bypasses traditional security alerts, such as password reset emails or failed login notifications, because it doesn't involve a conventional login process. The attacker is essentially using the victim's own authorization, albeit under false pretenses, to gain access. The compromise can persist until the attacker's device is manually removed from the victim's account settings.
To protect themselves, users are advised to exercise caution with unexpected requests, even from known contacts, and to avoid clicking on suspicious links. It is crucial never to follow instructions to link devices or scan QR codes unless the action was initiated by the user themselves. Regularly reviewing the 'Linked devices' in WhatsApp settings and enabling two-step verification can provide an additional layer of security.
If a user suspects their account has been compromised, they should immediately log out of all linked devices and notify their contacts to prevent further spread of the scam. Malwarebytes' Scam Guard is also highlighted as a tool that can help identify and block such malicious links and messages.