×

UPSC Courses

DNA banner

DAILY NEWS ANALYSIS

  • 30 January, 2026

  • 4 Min Read

GhostPairing

Recently, the Indian Computer Emergency Response Team (CERT-In) issued an advisory warning WhatsApp users about an active cyber threat campaign that uses a new attack technique known as GhostPairing. This method allows cybercriminals to take control of WhatsApp accounts without the user’s knowledge or authorization.

What is GhostPairing?

GhostPairing is a sophisticated WhatsApp account takeover technique in which hackers secretly link their own device to a victim’s WhatsApp account.

  • The attack gives near-complete access to the victim’s WhatsApp account.

  • It does not require passwords, SIM swapping, or physical access to the victim’s phone.

  • Hackers exploit the WhatsApp multi-device pairing feature by tricking users into sharing pairing codes.

Important Point: Victims often remain unaware that their WhatsApp account has been compromised.

How GhostPairing Works (Modus Operandi)

  1. Initial Lure Message
    Victims receive a message from a trusted contact saying, “Hi, check this photo.”

  2. Malicious Link with Social Media Preview
    The message contains a malicious link that displays a Facebook-style preview, making it appear legitimate.

  3. Fake Verification Page
    Clicking the link redirects users to a fake Facebook content viewer, which asks them to “verify” to view the content.

  4. Extraction of Pairing Credentials
    Victims are prompted to enter their phone number and WhatsApp pairing code.

  5. Account Takeover
    By entering these details, victims unknowingly link the attacker’s device to their WhatsApp account, granting hackers full control.

Impact of GhostPairing Attacks

  • Hackers can read messages, send messages, access contacts, and monitor communications.

  • Compromised accounts can be used to spread malware, conduct financial fraud, or target additional victims.

  • The attack exploits social engineering, rather than technical flaws, making it harder to detect.

Role of CERT-In

The Indian Computer Emergency Response Team (CERT-In) functions under the Ministry of Electronics and Information Technology (MeitY).

  • It is responsible for handling cyber security incidents, issuing advisories, and strengthening India’s cyber resilience.

  • CERT-In has advised users to avoid clicking suspicious links, never share verification or pairing codes, and enable additional security settings on WhatsApp.

Preventive Measures for Users

  • Do not click on unknown or suspicious links, even if they appear to come from trusted contacts.

  • Never share WhatsApp pairing or verification codes with anyone.

  • Regularly check linked devices in WhatsApp settings and remove unknown devices.

  • Enable two-step verification on WhatsApp for additional protection.

Conclusion

GhostPairing highlights the growing sophistication of cyber attacks that exploit user trust and social engineering rather than technical vulnerabilities. The CERT-In advisory underscores the need for digital awareness, cautious online behaviour, and proactive security practices to protect personal communication platforms like WhatsApp.



Source: INDIAN EXPRESS


India–Azerbaijan

A year after tensions arising from Operation Sindoor, India and Azerbaijan have taken steps to restore and normalise bilateral relations. The 6th round of Foreign Office Consultations, held in Baku, marked the first such engagement since 2022, signaling renewed diplomatic momentum. Recent Diplomatic Engagement During the consultations, bo

India–Australia Economic Cooperation and Trade Agreem

The India–Australia Economic Cooperation and Trade Agreement has completed four years since its signing. Both countries now aim to build on this progress through strengthened collaboration and ambitious targets, including reaching AUD 100 billion in bilateral trade by 2030. What is the India–Australia Economic Cooperation and Tra

ADR Report on Political Funding

A recent report by the Association for Democratic Reforms (ADR) analyses donations of ?20,000 or more declared to the Election Commission of India (ECI) by national political parties for FY 2024–25, highlighting transparency and accountability in political financing. Key Findings Massive Funding Surge Total donations to nationa

Maritime Chokepoints

Maritime chokepoints are narrow channels along global shipping routes where maritime traffic is concentrated. These points are geopolitically and economically critical, as they handle a large proportion of global trade, especially energy shipments. Current Relevance Over two-thirds of seaborne energy trade passes through a handful o

US-Israel-Iran War

Following the launch of Operation Epic Fury (U.S.) and Operation Roaring Lion (Israel), the geopolitical landscape has shifted fundamentally with the confirmed death of Iran’s Supreme Leader, Ayatollah Ali Khamenei.Iran retaliated through Operation True Promise 4, launching missile attacks against Israel and nearby Gulf states. The escala

DNA

05 Apr,2026

Toppers

Search By Date

Newsletter Subscription
SMS Alerts

Important Links

UPSC GS Mains Crash Course - RAW