WhatsApp phishing attack uses fake business docs to hack PCs
ID: cd735fea-7376-5cf1-89aa-6ddd933df14a
STIX ID: report--cd735fea-7376-5cf1-89aa-6ddd933df14a
Feed Name: Bleeping Computer
Kaspersky has identified a global WhatsApp-based malware campaign in which compromised accounts send obfuscated VBScript attachments named as business/financial documents; executing these files fetches scripts that modify the registry to disable UAC, download a ZIP containing ManageEngine Endpoint Central, and install/configure it to connect to attacker-controlled management servers, providing remote access. The campaign has been observed across multiple countries (including Brazil, India, Mexico, Singapore, the UK, Spain, Taiwan, Australia, Russia, Vietnam, and Malaysia); researchers note Chinese-language artifacts and infrastructure overlaps with ValleyRAT/Gh0st RAT activity but do not attribute with high confidence. Users are advised to verify files from contacts and scan downloads with up-to-date antivirus before execution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
