Kaspersky uncovers massive malware campaign on WhatsApp

  • DCV Desk
  • 28 Jun 2026, 05:55 AM
Kaspersky uncovers massive malware campaign on WhatsApp Photo: Courtesy
ad
In June 2026, Kaspersky GReAT accounts to send malicious attachments to trusted contacts. Disguised as routine business documents such as invoices and bank statements, the files exploit social engineering to increase downloads. Once installed, the malware enables remote system access. The campaign uses multilingual file names and VBScript metadata mimicking legitimate Windows Update components to evade suspicion, a press release said.
“In this campaign, attackers are exploiting trust within messaging platforms by using compromised WhatsApp accounts to deliver malicious attachments that appear to originate from known contacts, making recipients far more inclined to engage with them. The file names are carefully disguised as routine business documents, such as invoices and payment notices, and localized across multiple languages to support broad targeting. Once opened, they trigger a staged infection chain that silently retrieves and executes additional malicious components from external infrastructure,” says Fareed Radzi, security researcher at Kaspersky GReAT.
Once opened, the attachment launches a multi-stage attack, creating a directory, downloading additional scripts via Windows Script Host, and retrieving a compressed archive containing remote monitoring and management software for installation.
The full report is available on Securelist.com.
Kaspersky GReAT experts advise users to remain cautious when receiving unexpected attachments through WhatsApp, even if they appear to come from known contacts, as compromised accounts can be used to spread malware. Users should avoid opening script or executable file types such as .vbs, .vbe, .exe, .bat, .cmd, .js, and .ps1 unless their legitimacy has been independently verified. They also recommend using a strong security solution across all computers and mobile devices, such as Kaspersky Premium to detect threats and prevent infections.


Comment