logo

WhatsApp phishing attack uses fake business docs to hack PCs

ID: cd735fea-7376-5cf1-89aa-6ddd933df14a

STIX ID: report--cd735fea-7376-5cf1-89aa-6ddd933df14a

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2026-06-22

Date Updated: 2026-06-22

Author: Bill Toulas

...
...

Kaspersky has identified a global WhatsApp-based malware campaign in which compromised accounts send obfuscated VBScript attachments named as business/financial documents; executing these files fetches scripts that modify the registry to disable UAC, download a ZIP containing ManageEngine Endpoint Central, and install/configure it to connect to attacker-controlled management servers, providing remote access. The campaign has been observed across multiple countries (including Brazil, India, Mexico, Singapore, the UK, Spain, Taiwan, Australia, Russia, Vietnam, and Malaysia); researchers note Chinese-language artifacts and infrastructure overlaps with ValleyRAT/Gh0st RAT activity but do not attribute with high confidence. Users are advised to verify files from contacts and scan downloads with up-to-date antivirus before execution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.