Feed›Threat Intelligence›Russian hackers abuse WhatsApp device linking to spy on high...
Threat IntelligenceCyber Insider
8.5 — CRITICAL

Russian hackers abuse WhatsApp device linking to spy on high-value targets

📅 20 August 2026 at 18:35 UTC📰 Cyber InsiderView original source ↗
Russian hackers abuse WhatsApp device linking to spy on high-value targets

Three suspected Russian cyber-espionage clusters are abusing legitimate authentication features across WhatsApp, Google, and Microsoft to compromise academics, diplomats, defense personnel, researchers, and government-linked individuals. One cluster, tracked as UNC7005, has gone so far as to trick victims into linking WhatsApp accounts to attacker-controlled devices and recording their audio and video through fake calls. Google … The post Russian hackers abuse WhatsApp device linking to spy on high-value targets appeared first on CyberInsider.

🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview

Russian hackers have abused WhatsApp's authentication features to compromise high-value targets, including academics, diplomats, and government-linked individuals, using three suspected clusters with a Russian nexus.

⚙️Technical Details
Affected Systems
WhatsAppGoogleMicrosoft
Attack Vectors
device-linking request phishingmalware delivery through fake app downloadsOAuth token theft through fake file-sharing sitesmalicious Excel plugin (HEADRUSH)
💥Impact Assessment
Severity: high
Who Is at Risk
academicsdiplomatsdefense personnelresearchersgovernment-linked individualsSeverity: high
🛡️Recommended Actions
1Regularly review linked devices and enable two-step verification on WhatsApp accounts.
2Verify sensitive invitations through a separate trusted channel.
3Disable device-code phishing pages and OAuth access for suspicious requests.
📦Affected Products
WhatsAppGoogleMicrosoft

Read the full article

This is a curated summary. The complete article is available at Cyber Insider.

Read on Cyber Insider ↗
← Back to feed