started · updated
WhatsApp malware campaign distributes VBScript attachments to hijack PCs
Kaspersky has identified a large‑scale malware campaign that abuses compromised WhatsApp accounts to send malicious VBScript (.vbs) files to contacts on WhatsApp Desktop and WhatsApp Web. The attachments are disguised as routine business documents—such as invoices, bank statements or debt notices—and are localized in multiple languages (English, German, French, Portuguese, Malay, etc.). When a user opens the file, a staged infection chain creates a hidden directory, downloads additional scripts, modifies Windows User Account Control settings, and finally installs the legitimate remote‑management tool ManageEngine Endpoint Central, giving attackers full remote control of the infected PC.
The campaign has been observed in dozens of countries, with Malaysia accounting for roughly 80 % of detected infections. Other affected regions include Brazil, Singapore, Taiwan, Vietnam, India, Spain, the United Kingdom, Mexico, Australia, Russia and several others. Attackers leverage the trust inherent in messaging apps, using previously hijacked accounts so that the malicious files appear to come from known contacts. Kaspersky advises users not to open unexpected .vbs, .vbe, .exe, .bat, .cmd, .js or .ps1 files received via WhatsApp, even if the sender seems familiar, and to employ up‑to‑date security solutions.
The threat highlights the growing use of instant‑messaging platforms for phishing and the challenge of detecting VBScript‑based malware that bypasses many traditional antivirus defenses.