BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

WhatsApp Spreads Malware via RMM Software Scam

WhatsApp accounts hijacked globally to deliver malware via deceptive VBScript attachments.

  • WhatsApp accounts across 11 countries are being hijacked to distribute malware-laden VBScript files.
  • The campaign uses obfuscated scripts disguised as business documents to install legitimate RMM software for remote system access.
  • The infection chain manipulates Windows UAC and leverages previously seen infrastructure linked to Gh0st RAT and ValleyRAT.
  • Users in Malaysia have been the primary targets of this widespread social engineering attack.

Malicious actors have launched a global campaign using compromised WhatsApp accounts to deliver malware via direct messages, according to a recent report. This sophisticated social engineering scheme, active as of June 2026, primarily targets users in Malaysia, Brazil, India, and several other nations by distributing deceptive Visual Basic Script files.

- Advertisement -

The attack leverages hijacked accounts to send VBScript attachments masquerading as financial reports or account statements. Consequently, when executed, these heavily obfuscated scripts initiate a multi-stage infection process designed to install legitimate Remote Monitoring and Management software.

Security researcher Fareed Radzi from Kaspersky stated, “The threat actor uses deceptive file names masquerading as business and financial documents to persuade recipients to download and execute the attachment.” The scripts contain extensive comments written in Chinese, mimicking legitimate Windows Update components to evade detection.

However, the infection method differs slightly between WhatsApp Web and the WhatsApp Desktop application. In the desktop client, the malware is executed directly by the application’s background process, while web users must manually open the downloaded file.

The final payloads attempt to tamper with Windows User Account Control and fetch a ZIP file containing ManageEngine RMM Central. Meanwhile, infrastructure analysis revealed overlaps with previous malware campaigns, though the activity remains unattributed.

- Advertisement -

Kaspersky advises extreme caution with unexpected WhatsApp attachments, especially script or executable file types. Users should independently verify the legitimacy of any suspicious files before opening them.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Micron Defies Tech Selloff, Hits Record High Before Earnings

Micron (MU) stock hit a new all-time high on June 24, 2026, defying a...

Jefferies Sees Tesla Robotaxis as “Loss Centers”

Jefferies cut its Tesla price target to $375 and warned TSLA could start trading...

Ex-Ethereum Devs Launch Ethlabs to Woo Institutions

Former Ethereum Foundation contributors and firms Bitmine and Sharplink have funded a new nonprofit,...

Bitcoin Optimism Rises, but $70K Breakout Stalls

Bitcoin's funding rate climbed to 7%, signaling growing bullish confidence, but persistent spot ETF...

ShapedPlugin WordPress Backdoor in Supply Chain

Pro versions of three ShapedPlugin WordPress extensions were backdoored after attackers hijacked the official...

Must Read

How Much Money Do You Need To Start In Crypto?

TL;DR -If you are wondering How Much Money Do You Need To Start In Crypto, note that is less than you are probably thinking....
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading