< Back to all clusters
[TECHNOLOGY] · Malaysia · 5 sources

WhatsApp and Telegram hit by new malware campaigns

Cybersecurity firms have identified two separate malware campaigns that exploit compromised accounts on popular messaging platforms. Kaspersky reports a WhatsApp attack that distributes malicious VBScript files through WhatsApp Desktop and Web. The script creates a working directory, disables Windows UAC alerts, and downloads additional payloads, ultimately installing a ManageEngine Endpoint Central tool for full system access. The campaign is international, with Malaysia accounting for roughly 80% of detected infections, and investigators suspect a possible Chinese origin based on code comments and shared infrastructure.

Flare discovered a Telegram‑focused malware that steals session data from Telegram Desktop and Web. The PowerShell script gathers system information, forces Telegram to close, compresses the user’s data folder into a zip archive, and sends it to a Telegram bot before deleting the local copy. A second version targets Telegram Web by extracting MTProto keys from the browser’s local storage. While no real data exfiltration has been observed yet, the tools show active development and debugging.