logo

WhatsApp Phishing Attack Uses Fake Business Docs to Hack PCs

ID: b87911a2-5e26-55e0-98da-03645d5a8da1

STIX ID: report--b87911a2-5e26-55e0-98da-03645d5a8da1

Feed Name: CosmicBytez Labs

Threat Score
70/100

Date Published: 2026-06-22

Date Updated: 2026-06-24

...
...

**Active WhatsApp phishing campaign delivers VBScript droppers disguised as invoices and business documents, which fetch second-stage payloads that establish persistence (registry keys or scheduled tasks) and enable remote access capabilities such as keylogging and file exfiltration; the report includes observed IOCs (.vbs/.zip/double-extension attachments, outbound connections to obscure domains, task/registry changes) and recommended mitigations (disable/restrict VBScript, enable ASR, monitor wscript/cscript, user training).**

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.