New WhatsApp account attack doesn't require your password to succeed.Photothek via Getty ImagesEveryone knows that passwords need to be strong and unique, and they should be kept secret. But what if I were to tell you that a current WhatsApp attack campaign uses a combination of social engineering and a six-digit code to bypass the need for a password at all? Security experts at Malwarebytes Labs have confirmed that they are receiving ongoing reports of the attacks, which have been identified as “vote for my friend” scams, and have warned WhatsApp users to be on the alert. A successful compromise, the Malwarebytes report said, “allows the attacker to gain access to the victim’s WhatsApp account, enabling them to send messages, read chats, and harvest personal information.” Pieter Arntz, a malware intelligence researcher at Malwarebytes Labs, has detailed how the attackers are bypassing the need for your password by using a legitimate WhatsApp device linking feature and basic phishing methodologies to persuade users to authorize a new linked session “that gives the attacker access to your WhatsApp account.”ForbesX Scammers Deploy ‘Near-Exact Replicas’ Of Legitimate Login WarningsBy Davey WinderThe WhatsApp Voting Scam DissectedWhatsApp has a handy feature called device linking, which, as the name suggests, allows you to link multiple devices to a single account. The process is straightforward and secure. You go to the Linked devices option in your WhatsApp app, verify your identity using your biometrics, scan a QR code using the device to be linked and confirm you want to make the link. However, it is also possible to link a device using a phone number and a one-time code. And this, as you might have guessed, is where the new scam warning comes into play.Although the theme of the original scam message used in the WhatsApp attack will vary, it will always be related to an online voting request for a contest of some kind. Arntz said that Malwarebytes has seen variations including ballet competitions, best dog, and, of course, school prizes. “The wording is casual,” Arntz said, “sometimes urgent, and designed to get a quick click.” These messages leverage trust as they appear to come from a friend or relative, but the truth is that the person’s account has already been compromised.MORE FOR YOUIf the recipient falls for the ruse, and it’s really easy to do so when a friend is asking for such seemingly harmless help and clicks on the voting link, they are taken to a page “that appears to be related to WhatsApp,” Arntz warned, “often involving the legitimate wa.me domain, where the real attack begins.” You’re prompted to complete a connection or verification step, which is where the six-digit code comes in. Entering this is, in fact, providing the agreement to link your WhatsApp account to the device that is asking you to do so. A device that is controlled by the attacker. Once that connection is made, the threat actor can access your conversations until the device is unlinked. This means that they can impersonate you and forward more copies of the scam to your contacts, which is how the attack has been gaining traction. Of course, they can also employ other scams such as requesting money in “an emergency,” or simply harvest as much personal and sensitive information as possible about you. Remember, this bypasses the need to know your password. It doesn’t require a password reset that would trigger a notification and your suspicion. ForbesSearching For ‘The Odyssey’ Pirated Downloads Is A Risky BusinessBy Davey WinderMitigating The WhatsApp Voting Attack Campaign ThreatMalwarebytes recommends that WhatsApp users stay alert to the threat posed by such scammers and never, ever, share a WhatsApp verification code, “even if the request appears to come from someone you know.” Indeed, always verify any request to vote for someone with the sender directly, using a different method of communication than WhatsApp itself. Arntz added that users should enable WhatsApp two-step verification for extra protection as “it adds a PIN that can prevent attackers from taking over your account even if they obtain the SMS verification code.”Meta said that in order to help mitigate such device-linking scams, “WhatsApp will now alert you when behavioral signals suggest a linking request might be suspicious.” The new alerts will display the origin of the request and warn that it could be dangerous. A WhatsApp spokesperson said: “Users should never share their six-digit code with others, and we provide an overview of WhatsApp privacy settings.”