More on the topic...
Generating detailed summary...
Failed to generate summary. Please try again.
A wave of phishing messages on WhatsApp is pushing VBScript files disguised as business or financial documents. Attackers hijack legitimate contacts’ accounts, then send out files named things like “invoice_2023.vbs” or “financial_report.vbs” in the recipient’s local language. Kaspersky telemetry shows this campaign active in Brazil, India, Mexico, Singapore, the UK, Spain, Taiwan, Australia, Russia, Vietnam and Malaysia.
Opening the VBS kicks off a multi-stage infection. The script pulls down two more scripts, tweaks Windows Registry to turn off User Account Control, then retrieves and unpacks a ZIP containing the ManageEngine Endpoint Central client. That software installs silently and phones home to attacker-controlled servers, handing over full remote administration on the victim’s PC.
Researchers spotted Chinese-language artifacts in the code and some overlap with infrastructure linked to ValleyRAT and Gh0st RAT, but they stopped short of naming a culprit. How the attackers first broke into WhatsApp accounts remains a mystery.
If you use WhatsApp Web or Desktop, treat unexpected files—even from friends—with skepticism. Verify any attachment through a separate channel and scan everything with updated antivirus or endpoint protection before you run it.
Questions about this article
No questions yet.