WhatsApp accounts hit by malware campaign and SMS scams, experts urge two‑step verification
Kaspersky’s GReAT team reported an active malware campaign that uses compromised WhatsApp accounts to send files that appear to be invoices, bank statements or debt notices. The attachments carry a .vbs extension and, when opened, download additional components and install a legitimate remote‑management tool (ManageEngine Endpoint Central) as a backdoor. The campaign has been observed in Spain and also in Malaysia, Brazil, Singapore, Taiwan, Vietnam and Mexico. Spain’s national cybersecurity agency INCIBE confirmed the threat and advised users to avoid unexpected attachments.
Separately, Spanish police have warned of a surge in WhatsApp account hijackings that rely on unsolicited SMS verification codes. Attackers request the code from the victim, then gain full control of the account. Authorities recommend enabling WhatsApp’s two‑step verification PIN and never sharing verification codes, even if the request appears to come from a trusted contact.