The most common question I receive from novice hackers is, "How can I hack WhatsApp without touching the victim's device?" Today, I will demonstrate how a hacker can access a victim's account without physically interacting with the device or requesting an OTP, solely by using social engineering techniques.
Before diving into this information, let me clarify one thing to help you understand what we are going to do. WhatsApp has end-to-end encryption, making it nearly impossible to directly spy on or read a victim's WhatsApp messages. Different methods are employed under various conditions and situations, such as MAC spoofing, OTP phishing, SS7 attacks, and others.
QRLJacking
In this article, I’ll show you a method known as QRLJacking, in which the attacker sends a malicious link to the target device, tricking them into scanning their WhatsApp QR code. By doing so, the attacker can capture the WhatsApp Web session, allowing them to read, spy on, or respond to messages.
Requirements
- Linux/macOS (Linux Recommended)
- Firefox Latest Version
- Python 3.7+
Steps
- First of all, you have to download the driver for firefox and setup in your Linux system using the commands given below:
- Now download and set up the QRLJacking tool given commands
- Press Ctrl +C to intercept the QRJacker tool and type the commands given below:
- Now the list of saved sessions is shown on your Terminal (In my case "0")