Light bulb Limited Spots Available: Secure Your Lifetime Subscription on Gumroad!

Aug 25, 2026 · 7 min read

Russian Spies Are Phishing Your WhatsApp Linked Devices

Google's Threat Intelligence Group published research on 21 August 2026 on three suspected Russian espionage clusters that abuse login features working exactly as designed. The newest technique belongs to UNC7005, which spent May and June talking academics and diplomats into attaching an attacker controlled device to their WhatsApp account.

The QR code on the page is real. WhatsApp generated it, WhatsApp will honor it, and your phone accepts it without a warning. Nothing is counterfeit except the reason you were given for scanning. That is the trick, and why the security key in your pocket does nothing.

Key Takeaways

  • The Google Threat Intelligence Group is tracking three suspected Russian clusters, UNC6293, UNC7005 and UNC5976, that abuse legitimate login features rather than steal passwords.
  • In May and June 2026, UNC7005 ran phishing pages that lured targets into linking their WhatsApp account to an attacker controlled device to join a "secure" call, chat or file share.
  • The attacker feeds the target's phone number to WhatsApp and displays the genuine QR and linking code it returns, so the code the victim scans is authentic.
  • Once linked, the page offers a fake voice call whose JavaScript records the target's camera and microphone and uploads it to the attacker.
  • No password is taken anywhere in the chain, so multi factor authentication is never invoked and there is nothing to rotate afterward.
A smartphone on a dark desk in a dim study displaying a QR code, with an out of focus laptop screen glowing behind it

How Does the WhatsApp Linked Devices Scam Work?

The scam works by making the victim authorize a real WhatsApp device link on the attacker's behalf. According to Google's Threat Intelligence Group, the pages "lure targets into linking their WhatsApp accounts with an attacker controlled device in order to join a secure WhatsApp call, chat, or document share."

The mechanics are insultingly simple. The page asks your phone number. That number, GTIG writes, "is used to create a legitimate WhatsApp device link request with the attacker device, and then displays the legitimate QR and linking code to the target." You are watching a live handshake between WhatsApp and a machine in someone else's hands, rendered on a page you were told was a meeting invite.

GTIG names five domains: wa-connect[.]eu, wa-connect[.]net, wa-invite[.]com, wa-device[.]com and wa-meeting[.]com. None had to look convincing for long; the persuasion happened earlier, in the email.

What Happens After You Link the Attacker's Device?

The page then offers a voice call, an encrypted chat, or a file download. GTIG notes the attacker "attempts multiple other methods of compromise after the device is linked."

The voice call is the ugliest. Click it and the page calls navigator.mediaDevices.getUserMedia({ video: true, audio: true }) and starts a MediaRecorder capturing video/webm with vp8 and opus. In GTIG's words, the page "presents a fake voice call with a ring for a limited amount of time while the audio and video are recorded." When the call "fails," the blob is posted to /api/code/<session id>/recording. You think the connection dropped. The operator has video of you at your desk.

The chat option is a credential harvest in a privacy costume: the JavaScript prints a username and password beside a second URL at /chat/login and asks you to copy them over. As The Register reported, these clusters keep folding real authentication flows into phishing rather than faking logins.

Who Is UNC7005?

UNC7005, also tracked as STORM-2945, is a cluster GTIG identified in February 2026 that targets academia, diplomatic and nonprofit personnel across Ukraine, Western Europe and the US. Google assesses with moderate confidence that it is an initial access cluster tied to ICE RELIC, the actor formerly called APT29, and tracks it separately from UNC6293 for "its lower sophistication and poor operational security." A third cluster, UNC5976, tracked since March 2026, is genuinely distinct: heavier malware, and targeting aimed at the military, aerospace and defense industrial base in Ukraine and Armenia.

Both UNC6293 and UNC7005 also talk targets into generating Gmail app passwords, the technique we covered when Russian hackers bypassed Gmail MFA with app passwords in June. Two months on, the same orbit is running three variants of one idea.

Why Two Factor Authentication Does Not Stop Any of This

Two factor authentication does not stop these attacks because no authentication is ever bypassed. Every step is a legitimate action by the legitimate account holder. Device linking is a supported feature. So is an app password, and so is an OAuth consent screen. Your second factor fires, you approve it, and the attacker takes what comes out the other end.

Most coverage led with the OAuth token theft. The device link deserves more attention, because it leaves nothing to revoke by reflex: no password to change, no session to kill, only an entry in a settings list most people never open. What helps is the advice almost nobody follows: routine linked device audits, and Google's Advanced Protection Program, which removes app specific passwords entirely.

Device linking is not a WhatsApp quirk either. Signal and Telegram ship the same feature with the same QR handshake, so this lure ports to them with a new logo and nothing else.

What This Means for Your Inbox

Every one of these campaigns starts in email. Nobody stumbles onto wa-meeting[.]com by accident: a message arrives first, from a conference organizer or fellow researcher, carrying the link. GTIG documented a May 2026 wave sent from chamber-ua[.]org spoofing a summit on a resolution supporting Ukraine, aimed largely at US based academics and diplomats.

Email is where the OAuth variants live too. From 31 July to 13 August 2026, UNC7005 spoofed the Finnish Operations Center against the European defense industry. Targets who clicked "Sign in With Google" reached a real Google OAuth page, then landed on an unverified testing mode cloud project that GTIG believes stole their tokens. A real consent screen wired to an attacker's app is the pattern behind the EvilTokens OAuth device code phishing campaign against Microsoft 365 and the OAuth token abuse that opened Salesforce CRM data to attackers.

If you report, organize or research for a living, treat any message asking you to link, authorize or verify something as hostile until you confirm it through a channel the sender did not choose. A call to a number you already had beats scrutinizing the message.

How to Audit Your Linked Devices Right Now

GTIG advises "routine device audit checks for 'linked devices.'" That is five minutes of work:

  • WhatsApp: Settings, then Linked Devices. Each entry shows a platform and a last active time. Tap anything unfamiliar and log it out. See unlinking a device you do not recognize.
  • Signal and Telegram: same check. Signal: Settings, then Linked Devices. Telegram: Settings, then Devices.
  • Registration lock: turn it on, with two factor authentication, wherever it is offered. GTIG recommends this to stop an adversary registering your account with a stolen SMS code.
  • Google account: Security, then Your devices. Sign out anything unfamiliar, then revoke every app under Third party apps with account access that you do not actively use.
  • App passwords: Google says they "are not recommended and unnecessary in most cases" and "are not tools for account or identity verification." Follow its steps to remove app passwords from your account and delete every one you find.
  • Organizations: disable app specific passwords by restricting two step verification to "Only Security Keys," or enroll staff in Advanced Protection.

What to Watch Next

UNC5976 stood up at least twelve new domains within three months of GTIG disrupting it and is migrating off Google infrastructure, so expect the technique to resurface with less scrutiny. GTIG also flagged a PowerShell infostealer it calls CHERRYPIE whose "artifacts suggest the malware is generated by a large language model." Check your linked devices on a schedule, not after something goes wrong.

Source: Google Threat Intelligence Group, 21 August 2026.

Stop Email Tracking in Gmail

Spy pixels track when you open emails, where you are, and what device you use. Gblock blocks them automatically.

Try Gblock Free for 30 Days

No credit card required. Works with Chrome, Edge, Brave, and Arc.