Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts

A sophisticated hacking campaign, allegedly linked to Russian threat actors, has been exploiting a previously unknown vulnerability in Google’s OAuth authentication system to hijack user accounts on multiple platforms. The hackers are also using WhatsApp’s link-sharing feature to gain unauthorized access to sensitive information, leaving thousands of users vulnerable to identity theft and data breaches.

At the heart of this campaign is the abuse of Google’s OAuth protocol, which allows developers to integrate third-party services into their applications without requiring users to share their login credentials. While designed to simplify authentication, OAuth can be manipulated by attackers if not properly configured or managed. In this case, the hackers have been exploiting a zero-day vulnerability in the system to obtain authorization tokens, granting them access to high-value targets.

The attacks are often initiated through targeted phishing campaigns, where victims receive an email with a link that appears to come from WhatsApp. Upon clicking on the link, users are redirected to a legitimate-looking login page that mimics the actual WhatsApp authentication process. However, unbeknownst to the user, their device is secretly sharing sensitive information with the attackers, including their phone number and login credentials.

Once inside the system, the hackers can exploit the cross-domain privilege escalation vulnerability to access even more sensitive data, including financial and personal details. The attackers are reportedly leveraging this capability to map active attack paths, enabling them to pinpoint vulnerabilities in a user’s digital ecosystem and plan subsequent attacks accordingly.

The implications of these attacks are far-reaching, affecting users across multiple platforms and industries. The fact that WhatsApp link-sharing is being exploited highlights the importance of scrutinizing even seemingly innocuous interactions with third-party services. As the boundaries between different systems continue to blur, so too do the risks associated with cross-platform authentication and data sharing.

To mitigate these risks, we urge readers to exercise extreme caution when interacting with links from unknown sources. Always verify the authenticity of login pages and be wary of emails or messages that prompt you to share sensitive information. Furthermore, users should review their account settings and ensure that OAuth permissions are properly configured for all integrated services. By taking proactive steps to secure our digital identities, we can minimize the risk of falling victim to these sophisticated attacks.


Source: The Hacker News — 2026-08-20