Infosecurity

That ‘Vote for My Dog’ WhatsApp Message Could Hijack Your Account — Here’s How

Published

on

The Message That Seems Harmless

It starts with a ping. A friend — someone you actually know — asks for a tiny favor. Could you vote for their kid in a school contest? Or their dog in a cute-pet competition? The link looks fine. Sometimes it even uses WhatsApp’s own domain.

Don’t tap it. That’s the warning from Malwarebytes, which published new research on August 3 detailing a WhatsApp scam linked devices campaign that’s been spreading through compromised accounts.

The messages arrive from contacts whose accounts are already hijacked. They reference a ballet recital, a dog show, or a school event. The pretext varies, but the mechanics don’t.

What the Link Actually Does

The URL doesn’t lead to a voting page. Instead, it redirects to a page that mimics WhatsApp — often using the legitimate wa.me domain — and walks the victim through what looks like setting up WhatsApp Web. Other versions simply tell the target to open their linked device settings and punch in a code the scammer provides.

That’s the whole trick. There’s no password involved. No credential theft. Complete the flow, and the attacker’s device gets added as a linked session, giving them the same access as a legitimate second phone or computer.

What an Attacker Can Do Once Linked

Once in, they can:

  • Read all your private messages
  • Send messages as you
  • Follow conversations in real time
  • Forward the same scam to your contacts
  • Ask friends and family for money

Worse, there’s no alert. Because no login happens, there are no password reset emails or failed sign-in warnings. The rogue device just appears as another entry in your linked devices list. Malwarebytes says the compromise could go unnoticed for a long time unless you actively check.

A Familiar Trick With a New Costume

Abuse of the linked devices feature isn’t new. Researchers documented the same mechanism back in December 2025 under the name GhostPairing, which used fake photo-viewer pages instead of voting requests. Russian state actors have also used QR code and device-linking lures against WhatsApp and Signal users.

So what’s changed? The bait. A request to help someone’s child or pet win a contest is low-stakes, plausible, and comes from a real contact. Malwarebytes says that combination of trust and curiosity is what makes it so effective.

How to Protect Yourself From This WhatsApp Scam

The fix is straightforward but requires a bit of vigilance. Here’s what you should do right now:

  1. Open WhatsApp and go to Settings → Linked devices
  2. Review every device listed there
  3. Log out anything you don’t recognize
  4. Never scan a QR code or enter a linking code you didn’t initiate
  5. Verify unexpected requests through a different channel — call the person, don’t reply in chat

If you think you’ve already been hit, log out all linked devices immediately and warn your contacts that your account was compromised. The scam spreads through trust, so breaking that chain matters.

The Bigger Picture on Messaging Scams

This campaign is part of a broader wave of attacks targeting popular messaging apps. The NCSC security alert over hackers targeting WhatsApp and Signal from earlier this year shows how serious the threat has become. And it’s not just WhatsApp — Signal account hijacking attempts have also been on the rise.

The lesson is simple: treat any request to link a device or enter a code with suspicion, no matter who it comes from. A hacked friend’s account can send you a perfectly convincing message. The only defense is checking the source and verifying through another route.

For more on staying safe, check out our guide on spotting and avoiding messaging app scams. It covers the latest tactics and how to lock down your accounts before something goes wrong.

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending

Exit mobile version