Tushar Subhra Dutta at Cyber Security News reports that Russian-linked hackers are hijacking high-value accounts with a mix of phishing and legitimate sign-in features. The targets sit in government, defense, and academic shops. They are not smashing through firewalls. They are walking in through OAuth and WhatsApp device linking, the same tools you use every day to log in and read messages on a second screen.
That is the part that should make you sit up. The login looks real because it is real. You click, you approve, and they own the account.
OAuth Is a Permission Slip, Not a Magic Shield
OAuth is the system behind those Sign in with Google and Sign in with Microsoft buttons. You already know it. A site or an app asks for access. You say yes. The service hands over a token so you do not have to type a password every time.
Hackers love that flow. They send a phishing message that looks like a normal work notice. You land on a real sign-in page. You approve an application you did not mean to approve. After that, they do not need your password. They have a live token the system gave them because you said yes.
I have spent 30 years watching regular people get burned by convenient login tools. Convenience is a feature until somebody else is holding the keys.
WhatsApp Device Linking Hands Them Your Chats
WhatsApp lets you link a computer or another phone by scanning a QR code. That is device linking. It is built in. It is official. It is also a wide open gate if you scan the wrong code.
Trick someone into scanning a code on a page you control, and their phone treats your machine like a trusted device. Messages, contacts, group chats, the lot. For people in government, defense, and universities who treat WhatsApp like a work radio, that is the whole conversation walking out the door.
High-Value Targets, Everyday People
The report says the campaign is aimed at government, defense, and academic accounts. Those are high-value targets. The people clicking the links are not cartoon spies. They are staff, researchers, and contractors trying to get through their inbox.
That is how these jobs always work. You do not have to crack the vault if you can fool the person who has the combination. It pisses me off because the platforms built these linking features for ease, and the security model still leans on a human saying yes under pressure.
What This Means If You Use Email or WhatsApp at Work
You do not have to work at a defense lab for this to matter. OAuth tokens and linked devices show up in small businesses, churches, town offices, and family group chats. Same plumbing. Same risk.
- Do not approve a sign-in or an app permission you did not start yourself.
- Open your account settings and review connected apps. Yank anything you do not recognize.
- In WhatsApp, check Linked Devices and log out anything that is not yours.
- Treat a QR code like a password. If you did not walk over to your own computer to scan it, do not scan it.
- If you get a new-device or new-app alert, assume it is real until you prove it is not.
- Talk to the people around you. One rushed click is all it takes.
This is not about being paranoid. It is about treating login prompts and QR codes like the keys to the shop. Because that is what they are.
Primary Source: https://cybersecuritynews.com/russian-hackers-abuse-oauth-whatsapp/
