A new scam is circulating on WhatsApp, designed to take over user accounts by exploiting the platform's legitimate "Linked devices" feature. The attack typically begins with a message from a compromised contact, asking the recipient to vote for a friend or relative in an online contest, such as a ballet performance or a dog competition.
The initial message, often casual or urgent in tone, includes a link that appears to lead to a voting page. However, clicking this link redirects the user to a page that mimics WhatsApp's interface, sometimes involving the wa.me domain. This page then prompts the user to complete a verification, connection, or continuation step.
The scam's objective is to trick users into authorizing a new linked session, effectively granting the attacker full access to their WhatsApp account. This process often resembles the steps for setting up WhatsApp Web or linking a new device. Instead of stealing a password, the attackers leverage the user's unwitting consent to link their own device to the victim's account.
In some variations, the message or landing page instructs victims to open WhatsApp, navigate to "Connected Devices," and then enter a code provided by the scammer. This method also achieves the same outcome: linking the attacker's device to the victim's account.
Once an attacker successfully links their device, they gain significant control. They can read all messages, send messages as the victim, and access ongoing conversations in near real-time. This access allows them to perpetuate the scam by sending similar messages to the victim's contacts, request money or sensitive information from friends and family, and harvest personal data from chat histories.
A key aspect of this scam is its stealth. Since it doesn't involve a traditional login or password theft, there are no typical indicators like password reset emails or failed login alerts. The attacker's device simply appears as another linked session within the victim's account. Unless users actively check their linked devices, the compromise can remain undetected for an extended period.
Users are advised to exercise caution with unexpected "vote" or "support" requests, even if they originate from known contacts. It is crucial to avoid clicking unexpected links, especially those that immediately request verification or account linking. Users should never follow instructions to link devices or scan QR codes unless they have initiated the action themselves.
To protect against such attacks, WhatsApp users should regularly review their linked devices in the app's settings and log out of any unrecognized sessions. Enabling two-step verification adds an extra layer of security. If a message seems suspicious, it is recommended to verify its authenticity with the sender through an alternative communication channel before taking any action.
Examples of domains associated with this scam, though typically short-lived, include ngdance[.]fun/vote, fokindenfo1[.]lol/home/voteeeg3, stardancer[.]fun/home/voteCZ03, thebestscollato[.]top/home/scolatica, vatiter[.]click/home/voteerok, and megadencer[.]top/home/eng10. If an account is suspected of being compromised, users should immediately log out of all linked devices and inform their contacts to prevent further spread of the scam.






