BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

WhatsApp Spreads Malware via RMM Software Scam

WhatsApp accounts hijacked globally to deliver malware via deceptive VBScript attachments.

  • WhatsApp accounts across 11 countries are being hijacked to distribute malware-laden VBScript files.
  • The campaign uses obfuscated scripts disguised as business documents to install legitimate RMM software for remote system access.
  • The infection chain manipulates Windows UAC and leverages previously seen infrastructure linked to Gh0st RAT and ValleyRAT.
  • Users in Malaysia have been the primary targets of this widespread social engineering attack.

Malicious actors have launched a global campaign using compromised WhatsApp accounts to deliver malware via direct messages, according to a recent report. This sophisticated social engineering scheme, active as of June 2026, primarily targets users in Malaysia, Brazil, India, and several other nations by distributing deceptive Visual Basic Script files.

- Advertisement -

The attack leverages hijacked accounts to send VBScript attachments masquerading as financial reports or account statements. Consequently, when executed, these heavily obfuscated scripts initiate a multi-stage infection process designed to install legitimate Remote Monitoring and Management software.

Security researcher Fareed Radzi from Kaspersky stated, “The threat actor uses deceptive file names masquerading as business and financial documents to persuade recipients to download and execute the attachment.” The scripts contain extensive comments written in Chinese, mimicking legitimate Windows Update components to evade detection.

However, the infection method differs slightly between WhatsApp Web and the WhatsApp Desktop application. In the desktop client, the malware is executed directly by the application’s background process, while web users must manually open the downloaded file.

The final payloads attempt to tamper with Windows User Account Control and fetch a ZIP file containing ManageEngine RMM Central. Meanwhile, infrastructure analysis revealed overlaps with previous malware campaigns, though the activity remains unattributed.

- Advertisement -

Kaspersky advises extreme caution with unexpected WhatsApp attachments, especially script or executable file types. Users should independently verify the legitimacy of any suspicious files before opening them.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

GTA V mod adds 235 simulated Flock cameras to track players

Modder WTTDOTM has added 235 simulated Flock surveillance cameras to Grand Theft Auto V.The...

Tom Lee: Inflation Less Severe; Bullish on Ethereum

Tom Lee argues portfolio fees and flash memory prices distort inflation metrics, making the...

PayPal CEO rejects $50B buyout, charts an independent future

Paypal CEO Enrique Lores has rejected a buyout offer exceeding $50 billion from rival...

Bitcoin Suisse to shift up to half of its Swiss jobs abroad.

Bitcoin Suisse plans to relocate up to 60 of its 120 Swiss positions, primarily...

OpenAI Asks Congress if AI Rivals Can Legally Slow Development

OpenAI has asked lawmakers whether rival AI developers could legally coordinate a slowdown, according...

Must Read

Tutorial: How to Buy a Domain Name Permanently? (Super Easy)

Are you ready to establish a permanent online presence and you want to buy a domain forever?In this tutorial, we'll show you how to...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading