logo

Microsoft: Hackers Are Using WhatsApp to Deliver Malware to Windows PCs

ID: 650b47b4-4417-52bd-a74b-3ab21d47a24f

STIX ID: report--650b47b4-4417-52bd-a74b-3ab21d47a24f

Feed Name: TechRepublic Security

Threat Score
72/100

Date Published: 2026-04-01

Date Updated: 2026-05-05

Author: Joseph Ofonagoro

...
...

A recent campaign delivers malicious VBS attachments over WhatsApp to Windows desktops and web clients; clicking the attachment executes scripts that create hidden folders in C:\ProgramData, rename binaries to mimic system files, fetch payloads from trusted cloud services (AWS S3, Tencent Cloud, Backblaze B2), attempt UAC bypasses and registry modifications to achieve persistence, and ultimately install unsigned installers to enable backdoors and remote control. Microsoft researchers observed this wave beginning in late February and recommend improving endpoint controls, monitoring registry/UAC changes, enabling tamper protection, applying zero-trust principles, and blocking known C2 infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.