Add MobiGyaan as a preferred source on Google
Cybersecurity company Kaspersky has uncovered a large-scale malware campaign targeting WhatsApp Desktop and WhatsApp Web users through malicious VBScript attachments distributed via compromised WhatsApp accounts.
The campaign was discovered by Kaspersky’s Global Research and Analysis Team (GReAT) in June 2026 and has already affected users across multiple countries and territories. According to the company, Malaysia has recorded the highest number of observed victims, followed by several countries across Asia and Latin America.

Attackers Use Trusted WhatsApp Contacts to Spread Malware
According to Kaspersky, the attackers first gain access to WhatsApp accounts and then use those compromised accounts to send malicious attachments to existing contacts.
Because the messages originate from trusted friends, colleagues, or business contacts, recipients are more likely to open the attachments without suspicion.
The malicious files are disguised as legitimate business documents, including:
- Invoices
- Bank statements
- Account statements
- Payment records
- Debt notices
Kaspersky also observed malicious file names in multiple languages, including English, Portuguese, French, German, and Malay, suggesting a broad international targeting strategy.
To further evade suspicion, the VBScript files contain comments and metadata designed to resemble legitimate Microsoft Windows Update components.

Speaking on the findings, Fareed Radzi, Security Researcher at Kaspersky GReAT, said, “In this campaign, attackers exploit trust within messaging platforms by using compromised WhatsApp accounts to deliver malicious attachments that appear to come from known contacts, making recipients far more likely to engage with them. The file names are carefully disguised as routine business documents, such as invoices and payment notices, and localized across multiple languages to support broad targeting. Once opened, they trigger a staged infection chain that silently retrieves and executes additional malicious components from external infrastructure.”
How the Malware Infection Works
Once a victim opens the malicious VBScript file, the attack begins through a multi-stage execution process.
The initial script:
- Creates a working directory inside the Windows system
- Downloads additional scripts from attacker-controlled servers
- Executes the downloaded files using Windows Script Host
The secondary scripts then perform additional system actions before downloading a compressed archive containing a remote monitoring and management (RMM) tool.
Unlike traditional malware, the attackers leverage legitimate administrative software typically used by IT departments and system administrators. Once installed, the RMM software provides remote access capabilities that can be abused to control the infected system.
This approach allows attackers to blend malicious activity with legitimate administrative functions, making detection more difficult.
Countries Identified by Kaspersky
Kaspersky reported victims across multiple countries and territories, including:
- Malaysia
- Brazil
- Singapore
- Taiwan
- Vietnam
Malaysia recorded the highest number of observed infections during the investigation.
Security Recommendations
Kaspersky advises users to remain cautious when receiving unexpected files through WhatsApp, even if they appear to come from trusted contacts.
The company specifically recommends avoiding the execution of script-based and executable file formats unless their legitimacy has been independently verified.
Potentially dangerous file types include:
- .vbs
- .vbe
- .exe
- .bat
- .cmd
- .js
- .ps1
Users are also encouraged to keep security software enabled on both computers and mobile devices to detect and block malicious activity before infection occurs.
The discovery highlights a growing trend among cybercriminals who increasingly exploit trusted messaging platforms and compromised accounts to bypass traditional security awareness measures.
