WhatsApp continues to be the preferred target of cybercriminals looking to scam inattentive users. Authorities and security centers have issued an alert about a new attack campaign primarily targeting iPhone users. The method is particularly concerning because it allows attackers to steal the account without the victim needing to touch the device's screen.
This technique exploits vulnerabilities in WhatsApp's integration with other Apple services. Criminals manage to intercept verification codes and authentication data through automated methods, without needing physical access to the victim's device. The attack works silently, making its detection extremely difficult.
Affected users lose access to their WhatsApp account, also becoming exposed to additional scams. Attackers can use the stolen account to send messages to the victim's contacts, requesting money or personal information. This campaign represents a significant evolution in the social engineering tactics previously used.



