WhatsApp Phishing Attack Uses Fake Business Docs to Hack PCs
ID: b87911a2-5e26-55e0-98da-03645d5a8da1
STIX ID: report--b87911a2-5e26-55e0-98da-03645d5a8da1
Feed Name: CosmicBytez Labs
**Active WhatsApp phishing campaign delivers VBScript droppers disguised as invoices and business documents, which fetch second-stage payloads that establish persistence (registry keys or scheduled tasks) and enable remote access capabilities such as keylogging and file exfiltration; the report includes observed IOCs (.vbs/.zip/double-extension attachments, outbound connections to obscure domains, task/registry changes) and recommended mitigations (disable/restrict VBScript, enable ASR, monitor wscript/cscript, user training).**
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
