Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2253+ Articles
157+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. WhatsApp Phishing Attack Uses Fake Business Docs to Hack PCs
WhatsApp Phishing Attack Uses Fake Business Docs to Hack PCs
NEWS

WhatsApp Phishing Attack Uses Fake Business Docs to Hack PCs

An active malware campaign is targeting WhatsApp users across multiple countries with deceptive messages pushing VBScript-based droppers disguised as...

Dylan H.

News Desk

June 22, 2026
3 min read

Active WhatsApp Phishing Campaign Drops VBScript Malware via Fake Business Documents

Security researchers have identified an ongoing malware campaign exploiting WhatsApp as a delivery vector, targeting users across multiple countries with messages that impersonate legitimate business communications. The campaign uses weaponized documents to deploy VBScript-based malware, ultimately granting attackers remote access to infected systems.

Campaign Overview

The attack chain begins with unsolicited WhatsApp messages crafted to appear as routine business correspondence — invoices, delivery confirmations, purchase orders, or contract documents. Recipients who open the attached files trigger a VBScript dropper that silently installs remote access tooling on the victim's machine.

The messages exploit the trust users place in WhatsApp as a communication platform, and the business document lure is designed to lower suspicion — particularly in regions where WhatsApp is a primary business communication tool.

How the Attack Unfolds

  1. Lure delivery: Victim receives a WhatsApp message with an attached file claiming to be a business document (invoice, contract, PO)
  2. File execution: The attachment is a VBScript (.vbs) file, or contains an embedded VBScript that executes on open
  3. Dropper stage: The VBScript reaches out to attacker-controlled infrastructure and downloads the second-stage payload
  4. Persistence: Malware establishes persistence via Windows registry modifications or scheduled tasks
  5. Remote access: Attacker gains a foothold — enabling keylogging, file exfiltration, or further lateral movement

Geographic Targeting

The campaign has been observed targeting users in multiple countries, with particular concentration in regions where WhatsApp is heavily used for professional communications. The geographic breadth suggests either a financially motivated threat actor using wide-net phishing or a targeted campaign with broad regional scope.

Why VBScript?

Despite Microsoft's ongoing efforts to deprecate VBScript, the scripting engine remains enabled on many Windows systems — particularly in enterprise environments running older configurations. VBScript-based droppers are attractive to attackers because:

  • They blend in with legitimate administrative and business automation scripts
  • They can bypass some email/messaging attachment filters that focus on executable extensions
  • They require no compilation — rapid development and modification is trivial
  • Many endpoint detection tools still have gaps in VBScript behavioural analysis

Indicators of Compromise (IOCs)

  • Unsolicited WhatsApp messages with .vbs, .zip, or double-extension attachments (e.g. Invoice.pdf.vbs)
  • VBScript files impersonating document types (invoice, order, delivery)
  • Outbound connections to newly registered or obscure domains shortly after file execution
  • Scheduled task creation or registry run key modifications post-execution

Protection Steps

ActionPriority
Never open unsolicited attachments from unknown WhatsApp contactsCritical
Disable or restrict VBScript execution via Group PolicyHigh
Enable Windows Defender Attack Surface Reduction (ASR) rulesHigh
Monitor for suspicious scripting engine activity (wscript.exe, cscript.exe)Medium
Educate staff that WhatsApp is a common phishing vectorMedium

Key Takeaways

This campaign is a reminder that messaging apps are a significant and often under-monitored phishing surface. Unlike email, WhatsApp messages frequently bypass corporate security controls, and the informal nature of the platform lowers users' guard. Organizations operating in regions where WhatsApp is used for business communications should explicitly include it in their social engineering awareness training.


Source: BleepingComputer

#Phishing#Malware#WhatsApp#Social Engineering#VBScript

Related Articles

Ukraine Says Russian Intelligence Used Fake Support Texts to Steal Messaging Credentials

Ukraine's SSU and the FBI have exposed a sustained Russian intelligence campaign using fake support SMS messages to steal Signal, WhatsApp, and Telegram...

5 min read

WhatsApp VBScript Campaign Uses Fake Documents to Install ManageEngine RMM Tool

Attackers are abusing compromised WhatsApp accounts to distribute malicious VBScript files disguised as financial documents, ultimately deploying a...

4 min read

COLDCARD Security Audit Phishing Attack Installs Remote Access Tool

Attackers impersonating COLDCARD hardware wallet makers are sending fake 'security audit' emails to exploit user anxiety over the RNG vulnerability. Victims who run the downloaded batch file get ScreenConnect silently installed on their machine.

4 min read
Back to all News