Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

1577+ Articles
153+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. WhatsApp Phishing Attack Uses Fake Business Docs to Hack PCs
WhatsApp Phishing Attack Uses Fake Business Docs to Hack PCs
NEWS

WhatsApp Phishing Attack Uses Fake Business Docs to Hack PCs

An active malware campaign is targeting WhatsApp users across multiple countries with deceptive messages pushing VBScript-based droppers disguised as business documents, leading to remote system compromise.

Dylan H.

News Desk

June 22, 2026
3 min read

Active WhatsApp Phishing Campaign Drops VBScript Malware via Fake Business Documents

Security researchers have identified an ongoing malware campaign exploiting WhatsApp as a delivery vector, targeting users across multiple countries with messages that impersonate legitimate business communications. The campaign uses weaponized documents to deploy VBScript-based malware, ultimately granting attackers remote access to infected systems.

Campaign Overview

The attack chain begins with unsolicited WhatsApp messages crafted to appear as routine business correspondence — invoices, delivery confirmations, purchase orders, or contract documents. Recipients who open the attached files trigger a VBScript dropper that silently installs remote access tooling on the victim's machine.

The messages exploit the trust users place in WhatsApp as a communication platform, and the business document lure is designed to lower suspicion — particularly in regions where WhatsApp is a primary business communication tool.

How the Attack Unfolds

  1. Lure delivery: Victim receives a WhatsApp message with an attached file claiming to be a business document (invoice, contract, PO)
  2. File execution: The attachment is a VBScript (.vbs) file, or contains an embedded VBScript that executes on open
  3. Dropper stage: The VBScript reaches out to attacker-controlled infrastructure and downloads the second-stage payload
  4. Persistence: Malware establishes persistence via Windows registry modifications or scheduled tasks
  5. Remote access: Attacker gains a foothold — enabling keylogging, file exfiltration, or further lateral movement

Geographic Targeting

The campaign has been observed targeting users in multiple countries, with particular concentration in regions where WhatsApp is heavily used for professional communications. The geographic breadth suggests either a financially motivated threat actor using wide-net phishing or a targeted campaign with broad regional scope.

Why VBScript?

Despite Microsoft's ongoing efforts to deprecate VBScript, the scripting engine remains enabled on many Windows systems — particularly in enterprise environments running older configurations. VBScript-based droppers are attractive to attackers because:

  • They blend in with legitimate administrative and business automation scripts
  • They can bypass some email/messaging attachment filters that focus on executable extensions
  • They require no compilation — rapid development and modification is trivial
  • Many endpoint detection tools still have gaps in VBScript behavioural analysis

Indicators of Compromise (IOCs)

  • Unsolicited WhatsApp messages with .vbs, .zip, or double-extension attachments (e.g. Invoice.pdf.vbs)
  • VBScript files impersonating document types (invoice, order, delivery)
  • Outbound connections to newly registered or obscure domains shortly after file execution
  • Scheduled task creation or registry run key modifications post-execution

Protection Steps

ActionPriority
Never open unsolicited attachments from unknown WhatsApp contactsCritical
Disable or restrict VBScript execution via Group PolicyHigh
Enable Windows Defender Attack Surface Reduction (ASR) rulesHigh
Monitor for suspicious scripting engine activity (wscript.exe, cscript.exe)Medium
Educate staff that WhatsApp is a common phishing vectorMedium

Key Takeaways

This campaign is a reminder that messaging apps are a significant and often under-monitored phishing surface. Unlike email, WhatsApp messages frequently bypass corporate security controls, and the informal nature of the platform lowers users' guard. Organizations operating in regions where WhatsApp is used for business communications should explicitly include it in their social engineering awareness training.


Source: BleepingComputer

#Phishing#Malware#WhatsApp#Social Engineering#VBScript

Related Articles

Fake Microsoft Security Alerts Used to Deploy North Korean NarwhalRAT Malware

North Korean state-sponsored group APT37 (ScarCruft) is conducting spear-phishing campaigns impersonating Microsoft Account security notifications to...

4 min read

Sniper Dz Scams Target MENA Users via Fake Facebook Offers and Browser Alerts

Cybersecurity researchers have uncovered a large-scale phishing campaign by the Sniper Dz threat group targeting Middle East and North Africa users...

4 min read

ThreatsDay Bulletin: Worm Code Leaked, AI Agent Phished, Claude Code Patch + 28 New Stories

This week's threat intelligence roundup covers a supply chain attack kit posted publicly, a $5,000-per-month RAT that clones browser sessions, AI agents...

4 min read
Back to all News