WhatsApp malware campaign uses compromised accounts and fake business documents to install remote access on Windows PCs

Attackers are using hijacked WhatsApp accounts to send fake business and financial documents that infect Windows computers when opened. Kaspersky says the campaign delivers heavily obfuscated VBScript files through WhatsApp, then downloads additional scripts that modify User Account Control settings in the Windows Registry and silently installs ManageEngine Endpoint Central configured to connect to attacker-controlled servers. Victims have been seen in Brazil, India, Mexico, Singapore, the UK, Spain, Taiwan, Australia, Russia, Vietnam, and Malaysia.
Why it matters: People can be infected by files that appear to come from trusted contacts, turning a chat message into full remote access on their PC. Users should avoid opening script attachments from WhatsApp and verify unexpected files out-of-band; defenders should look for suspicious wscript.exe activity and unauthorized ManageEngine Endpoint Central installs.

Sources

WhatsApp phishing attack uses fake business docs to hack PCs
Bill Toulas 2026.06.22 100% relevant
This article establishes a distinct ongoing malware campaign centered on compromised WhatsApp accounts, localized fake document lures, and abuse of ManageEngine Endpoint Central for attacker remote access.
← Back to all stories