WhatsApp “Dancing Girl” Scam Returns with Fake Contests to Hijack Accounts

· Original article ↗

Summary

A phishing campaign uses fake dance-contest votes sent from compromised contacts to trick victims into linking an attacker-controlled device to their WhatsApp account, enabling message access and further scam propagation.

Key points

  • The scam message comes from a known contact whose WhatsApp account has already been compromised and asks recipients to vote for a dancer.
  • A convincing fake voting site asks victims to complete WhatsApp account verification after selecting a candidate.
  • The requested code authorizes an attacker-controlled device to link to the victim’s account; it does not validate the vote.
  • The victim’s phone may continue working normally, making the unauthorized linked session less noticeable.
  • Attackers can read conversations and use the compromised account to send the same scam to the victim’s contacts.
  • CERT-AGID advises checking linked devices, removing unknown sessions, enabling two-step verification, and not entering phone numbers or verification codes on sites reached through WhatsApp messages.

Article Details

Event Type
Phishing campaign using fraudulent voting contests to gain access to WhatsApp accounts.
Impact
Victims who enter the requested code can authorize an attacker-controlled device to link to their WhatsApp account. The device may remain linked without disrupting the victim's phone, allowing attackers to read conversations and send the scam to the victim's contacts.

MITRE ATT&CK

Products

Related Articles