ADEX Exposes WhatsApp Account Hijacking Scheme in Gaming Ads

In a startling revelation, ADEX, the anti-fraud and traffic-quality platform under AdTech Holding, has exposed a new WhatsApp account hijacking campaign cleverly disguised as a promotion for mobile gaming. This unsettling scheme was identified within the traffic of various clients and specifically targeted users residing in India, utilizing deceptive Popunder ads to lure in victims.

The campaign, which was first detected on July 20, 2026, employed a strategy where fraudsters fabricated a catalog of apps pertaining to Free Fire, a popular mobile game. This attention-grabbing approach aimed to entice users through a seemingly innocuous installation and prize verification process. However, the reality was far more sinister, as ADEX worked swiftly to identify and block this fraudulent endeavor.

Unpacking the Fraudulent Funnel


To fully comprehend the intricacies of this scheme, ADEX reconstructed the deceptive five-step funnel designed by the attackers. Here’s how it unfolded:
1. Initial Engagement: Victims encountered a page designed to mimic a legitimate catalog of gaming apps. Users were prompted to click a button that tricked them into thinking they were starting a download.
2. Data Collection: Instead of an actual download, users were invited to enter their phone numbers.
3. Verification Process: The interface then displayed an eight-digit code along with instructions resembling WhatsApp’s legitimate device linking process. Users were led to believe they were verifying an installation.
4. Malicious Link: Behind the scenes, attackers had initiated WhatsApp's legitimate linking process using their own browser. When users entered the eight-digit code, they unknowingly authorized the attacker’s browser as a trusted linked device.
5. Compromised Security: At this point, users continued to use WhatsApp as if everything was normal while the attackers accessed their messages and media via the linked session.

Evolving Tactics and Insights


This specific case provides critical insights into how fraudsters are evolving their tactics. According to Andrey Ivanov, CEO of ADEX, these criminals have transitioned from merely creating look-alike pages to developing actual conversion funnels. Their methods mirror legitimate advertising techniques by utilizing targeting, recognizable brands, and creating urgency to facilitate user engagement.

"Fraudsters have built mechanisms that optimize for account compromise at every stage of user interaction," Ivanov explained. The findings highlight the crucial need for businesses to adopt a more comprehensive approach to advertising and security. Reviewing only the ad creatives or the landing pages in isolation is no longer sufficient, as malicious activities can occur further along in the conversion journey, often after several redirects and user interactions have taken place.

The Importance of Vigilant Monitoring


As online advertising becomes more complex, it’s increasingly important for companies to implement end-to-end monitoring strategies that safeguard users throughout the conversion process. The tactics employed in this WhatsApp hijacking scheme illustrate how sophisticated these fraud attempts can be, making it imperative for advertisers to remain vigilant and proactive in their approaches.

Such revelations not only serve as a warning for the industry but also prompt advertisers to reconsider their security measures and user interaction protocols. In an age where digital threats are on the rise, ensuring the integrity and safety of user interactions is paramount.

As ADEX continues to refine its monitoring methods, the broader implications for the advertising sector are significant, pushing for a future where transparency and security play central roles in digital marketing strategies.

Topics Consumer Technology)

【About Using Articles】

You can freely use the title and article content by linking to the page where the article is posted.
※ Images cannot be used.

【About Links】

Links are free to use.