Cybersecurity firm Kaspersky has exposed an organized campaign spreading dangerous Visual Basic Script (VBS) files through WhatsApp to gain unauthorized access to user computers.
According to Secure List, the campaign targets users of WhatsApp Desktop and WhatsApp Web. Affected countries include Malaysia, Brazil, India, Mexico, Singapore, UK, Spain, Taiwan, Australia, Russia, and Vietnam. Malaysia has reported the highest number of victims.
According to cybersecurity researcher Farid Razi, attackers send fake files named as business and financial documents to trick users into downloading and opening them. Once opened, the file triggers a multi-stage cyber attack that installs Remote Monitoring and Management software on the victim’s computer.
Experts believe attackers are using previously hacked WhatsApp accounts to send these files to contacts. How initial access to WhatsApp accounts was gained remains unclear.
Kaspersky said the files appear to be financial or business documents. They are named “Financial Reports.vbs” and “Account Statement.vbs”. Some file names were also found in Portuguese, French, German, and Malay, indicating the global scope of the campaign.
The research found the files contain large amounts of fake code, comments, and metadata to make them look like legitimate Microsoft Windows Update components. Many comments are written in Chinese and reference Windows Update, system security, and certificate verification.
When the infected file runs, Windows “WScript.exe” downloads and executes additional scripts to complete the attack. WhatsApp Web users are at risk when they open the downloaded file thinking it is a legitimate document. In some cases, WhatsApp Desktop can execute the file directly through the application.
Investigations show the attack’s main goal is to download two additional VBScript files. One attempts to interfere with Windows User Account Control. The other downloads and installs the ManageEngine RMM Central software package on the computer.
Kaspersky warned users to be cautious of unexpected files received on WhatsApp, even if sent by known contacts. Experts advised against opening VBS, VBE, EXE, BAT, CMD, JS, and PS1 files without verification.
Cybersecurity experts said verifying suspicious files before opening and keeping antivirus software updated are critical to prevent such attacks.














