logo

WhatsApp on Windows users targeted in new campaign, warns Microsoft

ID: 7f95a6e7-314a-532f-99cf-3d5d614c94a4

STIX ID: report--7f95a6e7-314a-532f-99cf-3d5d614c94a4

Feed Name: Malwarebytes Blog

Threat Score
70/100

Date Published: 2026-04-01

Date Updated: 2026-04-28

...
...

Microsoft researchers discovered a WhatsApp attachment campaign that delivers .vbs files which, when executed by a user, copy and rename legitimate Windows tools to download additional scripts and an unsigned MSI installer that sets up remote-access payloads. The attack relies on social engineering, living-off-the-land abuse of built-in tools, cloud-hosted payload delivery to blend into normal traffic, and persistence via UAC/registry modifications.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.