CERT-In issues high-severity alert on WhatsApp GhostPairing attack
The Indian Computer Emergency Response Team (CERT-In) has issued a high-severity cybersecurity advisory warning users about an active threat campaign targeting WhatsApp accounts across India. The attack technique, known as GhostPairing , allows cybercriminals to take over WhatsApp accounts without passwords, OTP interception, or SIM swapping , raising serious concerns amid the surge in digital fraud and social engineering attacks.
How the GhostPairing attack operates
GhostPairing exploits WhatsApp’s multi-device (linked devices) feature . Attackers deceive users into entering a genuine-looking pairing code , which silently links the attacker’s browser as a trusted WhatsApp Web device. Once paired, the attacker gains continuous access to chats, contacts, and media, without triggering alerts on the victim’s phone or logging them out.
Phishing techniques used by attackers
The campaign typically begins with a message that appears to come from a known contact , often saying something like “Hi, check this photo.” The embedded link shows a Facebook-style preview and redirects to a fake viewer webpage . Victims are prompted to “verify” their identity by entering their phone number and a code. CERT-In clarified that this step completes the account takeover, even though the SIM card remains with the user.
Policy context and regulatory response
The advisory comes soon after the Department of Telecommunications (DoT) directed messaging platforms such as WhatsApp, Signal, and Telegram to implement continuous SIM binding . The aim is to reduce account hijacking and financial fraud, though the move has sparked debate around privacy, usability, and data protection .
Safety guidance from CERT-In
CERT-In has advised users to avoid clicking links , even from familiar contacts, and never enter phone numbers or codes on external websites. Users should regularly review the ‘Linked Devices’ section in WhatsApp settings and immediately log out of unknown sessions. Organisations have been urged to strengthen phishing awareness, monitoring, and incident response mechanisms .
Important Facts for Exams
-
CERT-In is India’s nodal agency for cyber incident response
-
GhostPairing exploits WhatsApp’s linked device feature
-
DoT has mandated continuous SIM binding for messaging apps
-
Messaging app hijacking is a major vector of digital fraud
Month: Current Affairs - December 25, 2025
Category: Cyber Security