Science, Discovery, Tech and Environment · 25 December 2025
CERT-In warns Indian WhatsApp users of GhostPairing attack hijacking accounts without passwords or SIM swaps
Exam-focused facts from the 25 December 2025 current affairs briefing.
Key facts
- GhostPairing allows cybercriminals to take complete control of WhatsApp accounts without requiring passwords or SIM swaps.
- The attack tricks users into granting an attacker’s browser access as an additional trusted and hidden device by using a pairing code that looks authentic.
- Victims receive a message from a trusted contact that reads: “Hi, check this photo” containing a link with a Facebook-style preview.
- The link leads to a fake Facebook viewer that prompts users to “verify” to see the content and then tricks them into entering their phone number and code.
- Once linked, attackers can access all chats, photos, videos, voice notes and impersonate victims to send messages to contacts and group chats.