Google OAuth and WhatsApp Linking Exploited in Account Takeover Scheme by Suspected Russian Hackers

Google OAuth and WhatsApp Linking Exploited in Account Takeover Scheme by Suspected Russian Hackers

Suspected Russian hackers are using Google OAuth and WhatsApp linking to take over user accounts. Understand the risk and learn how to protect your identity.

Cybersecurity researchers have identified a suspicious campaign in which hackers believed to be linked to Russia are abusing Google OAuth and WhatsApp linking to hijack user accounts. This technique combines two trusted authentication mechanisms to take over a victim's online identity.

Google OAuth is an open standard that allows websites and apps to let users sign in using their Google account. Instead of typing their Google password into a third-party site, the user clicks a button and is redirected to Google. Google then issues a token to the requesting app, granting it specific permissions without revealing the password. This is convenient, but it also has risks. If an attacker creates a malicious app and tricks a user into granting that app access, the attacker obtains a legitimate token. That token can be used to read emails, access cloud storage, or even act as the user in other services.

WhatsApp linking works in a similar way. It lets you use WhatsApp on a desktop or in a browser by scanning a QR code with your phone. Once you scan the code, your WhatsApp account is mirrored on that device. The attack takes advantage of this by sending a QR code or linking request to a target. If the target scans it, the attacker's device immediately gets a full copy of the victim's WhatsApp chats and can send messages in the victim's name.

The power of combining these two methods lies in identity chain takeover. If an attacker controls both your email and your WhatsApp, they can intercept password reset codes for other accounts. Many services rely on email or phone verification to reset passwords. With both Google email and WhatsApp under attack control, the attacker can lock you out of banking, social media, and corporate systems. This is why the campaign is so dangerous.

For website owners and IT teams, this attack emphasizes the need to monitor and control third-party OAuth applications. In Google Workspace, administrators can review which third-party apps have been granted access. They should revoke any app that is not necessary or that appears suspicious. Similarly, corporate policies should restrict the use of WhatsApp for business communications or enforce the use of official devices with security controls.

Users can defend themselves by taking a few practical steps. First, go to your Google account's security page and remove third-party apps you do not recognize. Second, enable two-factor authentication, which adds a second verification step beyond your password. Third, never scan a QR code from an unsolicited message. Fourth, if you use WhatsApp, check your linked devices in the app settings and log out from anything you do not recognize.

Businesses that want to strengthen their security posture should consider professional guidance. AEU-I delivers security-first IT, infrastructure and consulting, helping organizations audit identity and access controls to prevent account takeovers and other attacks. By combining proactive monitoring with employee awareness, companies can reduce the risk of falling victim to such schemes.

These evolving techniques show that account security is about more than just a strong password. Attackers are abusing legitimate features on big platforms, and every user needs to stay alert. Regularly review your app permissions, enable multi-factor authentication, and question any unexpected request to link your accounts. These simple habits can make a significant difference in keeping your digital life safe.

How to Protect Yourself

  1. Go to your Google account's security page, review the list of third-party apps with access, and remove any you do not recognize.
  2. Turn on two-factor authentication for your Google account and any important online accounts, using an authenticator app or a hardware key.
  3. Never scan a QR code from an unexpected email, text, or message, especially if it asks you to link your WhatsApp or log in to a service.
  4. If you use WhatsApp, check your linked devices regularly in Settings, and log out from any sessions you do not recognize.
  5. Keep your software and browsers updated to protect against known security weaknesses that attackers might use.

Related AEU services