A scam spreading on WhatsApp is talking people into handing over their entire account, and it opens with a request that sounds like nothing at all: vote for my friend. Malwarebytes picked the campaign up through the anonymised scam reports its users submit and published a breakdown of how it works.
The message usually arrives from a contact whose own account has already been taken over, which is exactly why it lands. A friend asks you to back someone in a ballet performance, a dog competition, a school event. The wording is casual, sometimes urgent, and built for a quick tap. The link does not lead to a voting page. It redirects to something dressed up to look like WhatsApp, often involving the legitimate wa.me domain, and that is where the real attack starts.
How the attack works
Rather than stealing a password, the scammers get victims to connect the attacker's device to their account through WhatsApp's own Linked devices feature, the same mechanism behind WhatsApp Web. Some versions of the scam walk the target through a flow that resembles setting up a new device. Others skip the fake page altogether and simply instruct the victim to open WhatsApp, go to Linked devices and type in a code the scammer supplies.
Either route ends the same way, with a second session on the account that the attacker controls. From there they can read conversations in near real time, send messages as the victim, forward the same scam to every contact, and ask friends and family for money or personal information. There is no password reset email and no failed login alert, because nothing was broken into. Unless the victim opens the linked devices list and looks, the access can sit there unnoticed for a long time.
Abusing WhatsApp as a delivery channel is now routine. Malwarebytes ranks it the third most common channel in the scam reports it receives, behind websites and email. On the malware side, recent cases include a Brazilian banking trojan that hijacks WhatsApp Web to spam a victim's contacts and fake Indian tax penalty notices delivering bank draining malware.
What you should do
Never link a device or scan a WhatsApp QR code unless you started the process yourself, and treat any unexpected prompt to verify or connect as hostile, including one that comes from someone you know. Open Settings, then Linked devices, and log out anything you do not recognise. Two step verification adds another barrier. If you think your account has already been linked to a stranger's device, remove every session immediately and warn your contacts, because reusing your name on them is the first thing an attacker does.
Malwarebytes published a handful of the domains behind the campaign, with the caveat that they are short lived and quickly replaced: ngdance[.]fun/vote, fokindenfo1[.]lol/home/voteeeg3, stardancer[.]fun/home/voteCZ03, thebestscollato[.]top/home/scolatica, vatiter[.]click/home/voteerok and megadencer[.]top/home/eng10.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.