WhatsApp “Vote for My Friend” Scam Takes Over Accounts

Malwarebytes · Medium sophistication
Last updated August 4, 2026

A WhatsApp scam spreads through messages that ask you to “vote” for a friend in an online contest. The link leads to a WhatsApp-looking flow that tricks you into linking your account to a device controlled by the attacker. Once linked, the attacker can read messages and impersonate you to scam your contacts.

Key findings

  • Attackers use a familiar “vote for my friend/relative” request, often sent from a compromised contact, to drive quick clicks.
  • Links do not lead to real voting pages; they redirect into a WhatsApp-themed flow (sometimes using the legitimate wa.me domain) designed to trick victims into linking a device.
  • The scam abuses WhatsApp’s legitimate “Linked devices” feature to create a new session controlled by the attacker.
  • Some variants instruct victims to open WhatsApp > Connected/Linked Devices and enter a code supplied by the scammer.
  • After linking, attackers can read messages, send messages as the victim, and propagate the scam to the victim’s contacts.
  • Because it’s not a traditional login, there may be no password reset emails or obvious login alerts; the linked device appears as another session.

Who’s being targeted

  • Commonly targeted roles: All employees, Executives, Customer-facing teams, Anyone using WhatsApp for work.
  • Affected industries: General public / consumers, Any organization using WhatsApp for business communications.
  • Attack channels: whatsapp, website.
  • Impersonated: A known contact (whose account may already be compromised).

Awareness takeaways

  • Treat unexpected “vote/support” requests as suspicious, even when they come from someone you know, and verify via another channel.
  • Don’t click links that quickly lead to ‘verify/connect/link your WhatsApp’ steps; that’s a common setup for account takeover.
  • Only link devices (or scan QR codes / enter codes) when you initiated the action yourself.
  • Regularly review WhatsApp Linked Devices and log out anything you don’t recognize to stop silent takeovers.

Red flags to watch for

  • Unexpected request to vote/support that tries to create urgency and get a quick click
  • Link leads to a WhatsApp-looking page prompting you to “continue, verify, or connect”
  • Any prompt to link a device/session that you did not initiate
  • Being told to link a device or enter a code you didn’t request
  • “Verification” steps that are not initiated by you
  • Requests coming from a friend/contact that feel unusual or out of character
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get a WhatsApp from a friend: “Hey, can you vote for my cousin in this contest?” Looks harmless, right? But the link doesn’t go to a voting page. It jumps into a WhatsApp-looking wa.me flow that pushes you to ‘continue’ or ‘connect’ your WhatsApp. Some versions even tell you: “open WhatsApp, go to Connected or Linked Devices, and enter this code.” That quietly links the scammer’s device to your WhatsApp so they can read and send messages as you. If a contact asks you to vote and you see any ‘verify, connect, or link your WhatsApp’ step, stop. Message them back on a different channel to confirm before you touch anything.

Similar attacks

Fake Fortnite Rewards Lure Epic Login Theft

Fake Fortnite Rewards Lure Epic Login Theft

Scammers are setting up fake Fortnite “rewards,” “locker value,” and “competition” websites that funnel players to a fake Epic Games login page. The sites trick people into signing in so attackers can steal Epic usernames and passwords, then take over accounts for resale, fraud, or further scams. A…

July 31, 2026
WhatsApp “Vote for My Friend” Scam Takes Over Accounts

WhatsApp “Vote for My Friend” Scam Takes Over Accounts

Attackers hijack WhatsApp accounts by sending a message from a compromised contact asking the recipient to “vote” in an online contest. Instead of a real voting page, victims are guided into linking the attacker’s device to their WhatsApp account, giving the attacker ongoing access to read and send…

August 4, 2026
Zero-Click Prompts Hijack AI Browsers via Email/X

Zero-Click Prompts Hijack AI Browsers via Email/X

Zenity demonstrated real-world attack chains where hidden instructions in emails or content on X can hijack AI “agentic browsers” (ChatGPT Atlas and the Claude Chrome extension). In the demos, the AI agent can be steered to perform actions in the user’s already logged-in sessions, sending phishing…

August 6, 2026
AI Browser Tricked into Spamming WhatsApp, Shopping

AI Browser Tricked into Spamming WhatsApp, Shopping

Researchers showed how a malicious web page could trick OpenAI’s Atlas AI-enabled browser into taking actions a user didn’t intend, like spamming WhatsApp contacts or modifying an Amazon account. The attacks used prompt-injection style instructions hidden in a seemingly legitimate “newsletter…

August 6, 2026
Hijacked Hotel Wi‑Fi Tricks Travelers Into Logins

Hijacked Hotel Wi‑Fi Tricks Travelers Into Logins

Microsoft says a Russian-linked group is abusing hotel and conference Wi‑Fi “captive portals” to trick travelers into entering corporate credentials or installing malware. Victims see what looks like a normal Wi‑Fi login flow, but attackers manipulate DNS/website traffic to redirect them to fake…

August 4, 2026
“Adult TikTok” Search Lures Drive Scam Funnels

“Adult TikTok” Search Lures Drive Scam Funnels

Scammers are using fake webpages that appear in search results for “TikTok” plus adult terms, promising “exclusive” explicit videos. Instead of any real content, the pages push visitors into an ad/affiliate funnel that collects emails, payment cards for fake “age verification,” or tricks people…

August 3, 2026