DFIR Tech Blog – an AI playground

Deutsch English
Foto von Markus Winkler auf Unsplash.com

Linked-Device Phishing: How Attackers Quietly Join Encrypted Chats

07.07.2026 mobile-forensiksignalwhatsappphishing

When a Feature Becomes a Weapon

Since early 2025, Google Threat Intelligence, the FBI, CISA, and several European intelligence agencies have been tracking an attack wave that requires no traditional vulnerability at all. The targets are Signal and WhatsApp accounts belonging to military personnel, diplomats, journalists, and increasingly corporate executives. The trick: instead of breaking encryption, attackers abuse the legitimate “linked devices” feature that lets a messaging account run on multiple devices at once.

The cluster Google tracks as UNC5792, overlapping with CERT-UA’s UAC-0195, achieves this by hosting modified Signal group invitations on actor-controlled infrastructure designed to appear identical to a legitimate Signal group invite, where the JavaScript that normally redirects to a Signal group is replaced by a malicious block containing the URI used to link a new device to the victim’s account. Because linking a device typically requires scanning a QR code, threat actors have resorted to crafting malicious QR codes that, when scanned, link a victim’s account to an actor-controlled Signal instance. The consequence: every future message is delivered synchronously to the attacker’s device in real time, providing persistent access — without touching the underlying cryptography.

WhatsApp has seen a structurally identical campaign dubbed “GhostPairing”: attackers exploit WhatsApp’s device-linking feature to hijack accounts using pairing codes, without requiring authentication. A joint FBI/CISA advisory from March 2026 confirmed that attackers did not break Signal’s encryption or hack the app itself, but instead used phishing to gain access to individual accounts, successfully compromising “thousands” of accounts linked to former U.S. officials.

Why This Is a Genuine Forensic Problem

For incident responders, this is exactly the difficulty: there’s no implant, no executed payload, no exploited CVE — just a user who trusted a crafted QR code or pairing code. The classic question, “what malware ran on the system?”, leads nowhere. Instead, the evidentiary weight shifts almost entirely to metadata and account structure:

What IR Teams Should Do Now

Organizations protecting executives, journalists, or otherwise high-risk personnel should add a dedicated “messenger account compromise” module to their playbooks: routine, documented checks of the linked-device list in Signal and WhatsApp, immediate awareness training tied to every “new device linked” alert, and a process to log linked devices forensically before removal. For regulated firms, the old tension resurfaces too: DOJ and SEC expect auditable retention of business communications, while CISA and the FBI explicitly recommend end-to-end encrypted messengers for security reasons. This campaign is a reminder that even the strongest encryption cannot protect a user who scans the wrong QR code — and that forensic teams increasingly need to work with evidence-poor compromises where the strongest trace left behind is just a device list.

← Back to overview