Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

WhatsApp account takeover scam asks you to "vote for my friend"

0
Medium
Published: 08/04/2026 (08/04/2026, 07:17:39 UTC)
Source: AlienVault OTX General

Description

A sophisticated scam is spreading through WhatsApp that exploits the platform's legitimate 'Linked devices' feature to take over user accounts. Attackers compromise existing accounts and send messages to contacts asking them to vote for a friend or relative in various online contests. When victims click the provided link, they are redirected through pages appearing to be WhatsApp-related, often using the legitimate wa.me domain. The attack tricks users into authorizing a new linked session, granting attackers full access to read messages, send messages as the victim, and access contacts. The scam is particularly effective because it comes from known contacts and relies on trust and quick reactions. Once compromised, attackers can continue the scam by messaging the victim's contacts, creating a chain of account takeovers without triggering traditional security alerts.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/04/2026, 09:37:10 UTC

Technical Analysis

This campaign abuses WhatsApp's 'Linked devices' feature by sending phishing messages from compromised accounts to their contacts. The messages contain links that redirect through pages mimicking WhatsApp, often using the legitimate wa.me domain, to trick victims into authorizing a new linked session. Once authorized, attackers gain full access to the victim's WhatsApp account, including reading and sending messages and accessing contacts. The attack propagates by using compromised accounts to target their contacts, creating a chain of account takeovers. The campaign relies heavily on social engineering and trust within contact networks.

Potential Impact

Successful exploitation results in full takeover of WhatsApp accounts, allowing attackers to read private messages, send messages impersonating the victim, and access the victim's contacts. This enables further propagation of the scam and potential additional fraud or social engineering attacks. The scam does not exploit a software vulnerability but abuses legitimate platform features combined with social engineering.

Defensive Guidance

No official patch or fix is applicable as this is a social engineering campaign abusing legitimate WhatsApp features. Users should be educated to avoid clicking unsolicited links, especially those asking to authorize new linked sessions. Verification of such requests through direct communication with the contact is recommended. WhatsApp users should regularly review their linked devices and remove any unknown sessions. Monitoring official WhatsApp security advisories for updates is advised. Patch status is not applicable; this is a user behavior and awareness issue.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.malwarebytes.com/blog/scams/2026/08/whatsapp-account-takeover-scam-asks-you-to-vote-for-my-friend"]
Adversary
null
Pulse Id
6a719213d506eb46339cc1dd
Threat Score
null

Indicators of Compromise

Domain

ValueDescriptionCopy
domainngdance.fun
domainfokindenfo1.lol
domainstardancer.fun
domainthebestscollato.top
domainvatiter.click
domainmegadencer.top

Url

ValueDescriptionCopy
urlhttp://fokindenfo1.lol/home/voteeeg3
urlhttp://megadencer.top/home/eng10
urlhttp://ngdance.fun/vote
urlhttp://stardancer.fun/home/voteCZ03
urlhttp://thebestscollato.top/home/scolatica
urlhttp://vatiter.click/home/voteerok

Threat ID: 6a71a049bf32cb7a340157eb

Added to database: 08/04/2026, 08:18:17 UTC

Last enriched: 08/04/2026, 09:37:10 UTC

Last updated: 08/04/2026, 12:38:57 UTC

Views: 19

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses