
How Cybercriminals Hijack Abandoned WhatsApp Groups—And Turn Them Against You
They don’t hack WhatsApp—they hack people. This investigation uncovers how attackers use publicly shared invite links and psychological intimidation to take over abandoned WhatsApp groups, exposing a growing threat to thousands of community networks.
Are you an admin of WhatsApp groups?
Are you keeping track of where the join links are shared?
Have you ever considered the possibility of your WhatsApp group being hijacked?
Then that’s exactly what happened to Sourav (name changed for privacy concerns).
Sourav was happy to share his odd experience with Offbeat Concerns.
As monsoon-triggered floods batter parts of India, WhatsApp groups have once again become vital for sharing alerts, coordinating rescue efforts and mobilising help. From disaster response and blood donation drives to neighbourhood and family networks, these groups play an important role in connecting people. But their open invite links and abandoned administration can also make them vulnerable to misuse and hijacking.
This investigation explores Sourav’s experience and examines how cybercriminals targeted the WhatsApp groups he administered, their methods of operation, and their objectives in seizing control of these groups. The story also includes guidance for group administrators if their WhatsApp groups are hijacked.
Sourav is based in Thiruvananthapuram and has created several WhatsApp groups, serving as the sole administrator to organise blood donors and meet urgent blood requirements for those who are in need. Those groups had remained inactive for some time, with most of the members already having left, before Sourav noticed something unusual on WhatsApp.
On July 27, Sourav opened WhatsApp to find that all the groups had been defaced, with their names and icons changed. He also noticed that a new WhatsApp user with a Pakistani mobile number, +923077627219, had joined the groups.

The names of the groups were changed to ‘VirusData/Heck’ after numbers ‘+92 307 7627219’ and ‘+1 (201) 246-6710’ joined them. Soon after, a message was also shared tagging Sourav that read, “You’ll have one chance. Leave the group because I’m hacking WhatsApp. Last warning: leave the group.”

This message was sent multiple times across the defaced groups, intimidating Sourav to leave them.
This was not the first time.
After a preliminary analysis of the matter, we found that this was not the first such incident. On March 17, a Facebook user shared a post describing a similar experience involving her friend.

The screenshots shared along with the post reveal that the Pakistan-based WhatsApp user ‘+92 307 7627219’ was involved in a similar hijacking attempt in the past.
How do they join these groups?
We found that in all these cases, the actors behind the group takeover joined the group using the group join link. Sourav admitted that after the blood donation groups were created, the join links were widely shared on Facebook and other similar platforms.
From an attacker’s perspective, these group links were extremely easy to find using structured keywords. Since these links were shared as public posts, anyone who finds them can join the group, including cybercriminals.
Intimidating the admin
The next tactic used by these actors is to intimidate the group’s admin into leaving. If the sole admin leaves a WhatsApp group, WhatsApp automatically picks another participant at random to become the new admin.
Thus, if the attacker joins a WhatsApp group where only the admin is present and, after defacing the group, the administrator panics and leaves, the attacker will be chosen as the next admin, thereby hijacking the group for illicit purposes.
Why was Sourav’s WhatsApp group hijacked?
There are numerous ways these hijacked groups may be used. In Sourav’s case, we noticed that a Pakistan-based WhatsApp number shared an image that appeared to depict a hacking tool.

The image suggests that the tool identifies itself as an ‘FB Cracking System’.
What did we find?
A deeper OSINT investigation into the matter led us to a GitHub repository hosting the tool.

We also discovered a Facebook group (the name of which is purposefully withheld for security reasons) where multiple users shared posts on how to use this tool, clearly listing the steps. The post also included a link to a WhatsApp group dedicated to hacking-related discussions.

Although no direct attribution can be made, the discovery indicates that the tool was being promoted through interconnected online communities, with Facebook posts serving as an entry point to WhatsApp groups where hacking-related discussions took place.
Static code analysis of the GitHub files.
To better understand the tool’s capabilities, a static analysis was conducted to examine its structure, embedded functions, and compiled modules. The repository contained three launcher scripts and three compiled Python extension modules for Android, intended to run in a Termux environment.
While the launcher scripts merely executed the compiled binaries, the analysis recovered several function names, including login, login_lagi334 and cookie_remover, alongside variables such as cookie, token, accessToken and bot_token. Additional functions labelled api1, api2 and api3 suggest multiple API-based workflows, while references to Android device information indicate the application gathers basic system details during execution.
The application’s interface openly identifies itself as an ‘FB Cracking System’ and provides options to create files of target IDs. However, because the core logic is compiled into native ARM64 machine code, static analysis alone cannot determine how these functions operate internally. No hard-coded command-and-control domains or obvious exfiltration endpoints were identified during the initial analysis.
Consequently, while the binaries confirm authentication-, cookie- and token-related functionality, they do not, by themselves, establish that the application steals credentials or compromises Facebook accounts.
What to do if your WhatsApp group is hijacked?
If you find yourself in a similar situation where someone has joined and defaced your WhatsApp group and is intimidating you into leaving, please keep the following points in mind.
Remove unauthorised members and admins as soon as they are identified. Review the group’s admin list to ensure only trusted individuals retain administrative privileges.
Restrict the group invite link. If the group link has been shared publicly or appears compromised, reset it and generate a new invitation link.
Enable admin-only permissions to change the group description, settings, and posting, if appropriate. This helps prevent further misuse while the situation is being resolved.
Review the ‘View Member Changes’ history. WhatsApp records recent joins, exits and admin changes, which can help identify how the takeover occurred.
Warn group members not to click on suspicious links, download shared files or respond to threats posted by the intruders.
Report the group and offending accounts through WhatsApp’s reporting feature if the group is being used to distribute scams, malware or other harmful content.
Document everything before making changes to the group. Take screenshots of the altered group name, profile picture, messages and membership changes before restoring the group. These records may be useful if the incident needs to be reported to law enforcement or investigated further.
Sourav’s experience serves as a reminder that even dormant WhatsApp groups can become attractive targets when publicly shared invite links remain accessible online. While the intimidation tactics employed by the actors were intended to pressure the sole administrator into abandoning the groups, the incident also highlights a broader security concern affecting thousands of forgotten community groups created for social causes, educational activities, and volunteer work.
This investigation found that the actors relied on publicly available group invite links and attempted to gain administrative control through social engineering rather than exploiting a technical vulnerability in WhatsApp itself. Although the associated tool was marketed as an ‘FB Cracking System’, static analysis alone could not conclusively establish its exact capabilities.
For group admins, the lesson is simple: periodically review old groups, regenerate invite links where necessary, maintain more than one trusted administrator and remain cautious if unknown members suddenly appear or begin intimidating participants. In many cases, timely action may be enough to prevent a dormant community from being repurposed for malicious activities.

Sujith A
Open Source Intelligence Researcher and Mis/Disinformation tracker. Passionate about investigations and a big fan of Sherlock Holmes.
View all posts by Sujith A