New Cyber Threat Involving WhatsApp and Google Login: How to Stay Safe?
WhatsApp and Google Login have become essential parts of our digital lives. However, cybercriminals are now exploiting these very features to target individuals.
We often rely on WhatsApp and Google Login to access accounts, open files, or connect to services; yet, cybercriminals are now misusing this trust and the legitimate authentication process. Recently, the Google Threat Intelligence Group (GTIG) reported activities by three suspected Russian cyber-espionage groups—UNC6293, UNC7005, and UNC5976—targeting individuals associated with academia, aerospace, defense, government institutions, and think tanks in Europe and the US. Here is how you can protect yourself from these new cyber threats involving WhatsApp and Google Login.
How are scammers exploiting WhatsApp and Google Login?
Cybercriminals do not always target people using fake login pages. Groups like UNC5976 use "OAuth Phishing" to direct users to the legitimate Google login page. When a user logs in normally, the scammers attempt to obtain an authentication token via a cloud project under their control. Once they acquire this token, they can attempt to gain access to the user's account. Similarly, UNC7005 used fake domains and cloud infrastructure to direct users to the genuine Google OAuth login page and attempted to steal authentication tokens after the login process.
Risks Associated with WhatsApp Linking
Cybercriminals are also misusing WhatsApp's "Device Linking" feature. Users are lured with the promise of joining a secure call, chat, or document-sharing session. They are then asked to provide their phone number and link their device using a displayed QR code or linking code. If a user inadvertently links the attacker's device to their WhatsApp account, the attacker can attempt to read chats, send messages, and access private information. In some instances, fake pages have also been used to present options for voice calls, encrypted chats, or file downloads.
How to protect yourself from new cyber threats targeting WhatsApp and Google logins:
1. Always keep Two-Step Verification enabled to secure your WhatsApp account. This adds an extra PIN, providing an additional layer of security.
2. You can also use WhatsApp Passkeys, which are linked to your phone's fingerprint, face unlock, or screen lock features.
3. Additionally, do not accept device linking requests from unknown or suspicious sources, and never share your WhatsApp verification code with anyone.
4. Make use of features such as silencing unknown calls, reviewing your settings via the Privacy Check-up, and blocking or reporting suspicious messages.
5. Avoid logging in via unknown links or suspicious websites. If a link directs you to a Google login page, do not trust it simply because the page looks authentic.
6. In OAuth phishing attacks, scammers may direct users to a genuine-looking Google login page to steal authentication tokens. Therefore, carefully check login requests from unknown domains and avoid clicking on any suspicious links.

