logo

Alert: WhatsApp Phishing Campaign Delivers Malware

ID: 2d20ccaa-3273-5fe7-b461-d9148f5aca27

STIX ID: report--2d20ccaa-3273-5fe7-b461-d9148f5aca27

Feed Name: KnowBe4 Blog

Threat Score
70/100

Date Published: 2026-04-21

Date Updated: 2026-04-28

Author: KnowBe4 Team

...
...

A Microsoft-reported phishing campaign uses WhatsApp messages to trick users into running malicious VBS files that create hidden folders, deploy renamed legitimate Windows utilities to evade detection, download payloads hosted on trusted cloud services (AWS, Tencent Cloud, Backblaze B2), and install MSI packages for persistence. Microsoft recommends strengthening endpoint controls (restricting script hosts and monitoring renamed utilities), enhancing cloud traffic monitoring, detecting persistence/UAC tampering, blocking known C2 infrastructure, and user training to mitigate the threat.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.