An ongoing cyber campaign targeting WhatsApp users is using fake business documents to trick recipients into installing malware on their computers. According to cybersecurity firm Kaspersky, compromised WhatsApp accounts are being used to spread malicious files that give attackers remote access to infected systems.
The attacks have been detected in several countries, including Brazil, India, Mexico, Singapore, the United Kingdom, Spain, Taiwan, Australia, Russia, Vietnam, and Malaysia.

Fake documents sent from trusted contacts
The attacks begin when users receive a message from a contact whose WhatsApp account has previously been compromised. The message contains a VBScript file that pretends to be, for example, an invoice, financial report, or business document.
The file names are adapted to different languages and markets, which according to Kaspersky shows that the campaign has a global reach.
Kaspersky states that the exact method behind the hijacking of the WhatsApp accounts is still unknown.
– Based on evidence collected from multiple victims and analysis of submitted samples, we can conclude that the threat actor has gained access to multiple WhatsApp accounts and used them to distribute malicious VBScript files to contacts in the compromised users' contact lists, writes Kaspersky.
Legitimate tool used in the attack
If the recipient downloads and opens the file on a Windows computer, it starts a chain of scripts that download additional files from the attackers' servers.
The scripts make changes to the Windows registry to reduce security protection and then download a ZIP archive containing the ManageEngine Endpoint Central software.
The software is typically used by IT administrators for centralized management of computers and servers, but in this campaign it is used to give attackers remote access to the infected computer.
The installation occurs in the background and is configured to connect to attacker-controlled servers, allowing remote control of the affected device.
Differences between WhatsApp Web and the desktop app
Kaspersky notes that WhatsApp Web users must first download the malicious file before it can be executed.
IN WhatsApp desktop app, however, the file can be opened directly via Windows Script Host, which simplifies the attack and increases the risk of users unknowingly activating the malicious code.
Possible connections to previous threat actors
Researchers have not yet been able to link the attacks to any specific threat actor, but the analysis does show some indications of Chinese language usage and infrastructure that have previously been associated with malware such as ValleyRAT and Gh0st RAT.
At the same time, Kaspersky emphasizes that there is not sufficient evidence to make a confident attribution.
How to protect yourself
Kaspersky recommends that users always handle files sent via messaging services with caution, even when they come from people they know.
The security company recommends that users:
- Verify suspicious files with the sender via another communication channel.
- Avoid opening unknown script files or executable files.
- Scans downloaded files with an updated antivirus program.
- Keeps operating systems and security programs updated.
- Be extra cautious with documents that claim to contain financial or business-related information.








