Kaspersky: New massive malware campaign via WhatsApp
Source: PR
Wednesday, 24.06.2026.
09:16
Wednesday, 24.06.2026.
09:16
(Photo: Alejandro Ruhl/shutterstock.com)
Victims have been identified in multiple countries and territories, with the highest number of victims reported to be located in Malaysia.
The use of multiple languages in the file names also suggests broad regional targeting, particularly across Europe.
Messaging via existing contacts
The campaign was discovered in June 2026 by Kaspersky’s Global Research and Analysis Team (GReAT).
According to their research, the actor behind this criminal activity uses previously compromised WhatsApp accounts to distribute malicious attachments.
Messages are sent to contacts that already exist in the compromised accounts, increasing the likelihood that recipients will open the files.
Once installed, the malware allows remote access to the system using standard administrative functionalities intended for legitimate IT support and system management.
The social engineering component relies on file names designed to resemble common business documents.
Examples observed include invoices, bank statements, account balance statements, payment records, and debt notices.
The file names are also localized into multiple languages, including English, Portuguese, French, German, and Malay, indicating distribution across multiple language regions.
Additionally, the sample VBScript files contain extensive comments and metadata designed to mimic legitimate Microsoft Windows Update components.
Examples of WhatsApp messages containing a malicious VBScript file (Photo: Kaspersky/ Društvene mreze)
– In this campaign, attackers exploit trust within messaging platforms by using compromised WhatsApp accounts to deliver malicious attachments that appear to come from known contacts, making recipients more likely to interact with them.
The file names are carefully disguised to look like routine business documents, such as invoices and payment notices, and are localized in multiple languages to support broad targeting.
Once opened, they trigger a multi-stage infection chain that silently downloads and executes additional malicious components from external infrastructure – said Fareed Radzi, a security researcher with Kaspersky GReAT team.
The execution flow of the attachment follows a multi-stage process on the compromised system.
Once opened, the file runs a scripted sequence on the device. The initial script creates a working directory in C:/Users/Public/Documents/, after which it downloads additional script files from external infrastructure and executes them using the Windows Script Host component.
These subsequent scripts perform additional actions on the system and download a compressed archive from the same infrastructure.
The archive contains an installation package for Remote Monitoring and Management software.
The full report is available on Securelist.com.
Kaspersky GreAT Team experts recommend that users:
• Be cautious when receiving unexpected attachments via WhatsApp, even when they appear to come from familiar contacts, as they may contain malware.
• Do not open scripts and executable files such as .vbs, .vbe, .exe, .bat, .cmd, .js, and .ps1, unless their legitimacy has been independently verified.
• Use a reliable security solution on all computers and mobile devices, such as Kaspersky Premium, that will alert the user and prevent potential infection.
About the Global Research & Analysis Team (GReAT)
Established in 2008, the Global Research & Analysis Team (GReAT) is at the heart of Kaspersky’s research activities and is dedicated to uncovering APT (Advanced Persistent Threats), cyber-espionage campaigns, high-profile malware, ransomware, and trends in the cybercrime underground worldwide.
Today, GReAT brings together more than 35 experts working across Europe, Russia, Latin America, Asia and the Middle East.
These top information security experts lead the company in malware research and innovation, bringing unique knowledge, dedication and curiosity to the detection and analysis of cyber threats.
Companies:
Kaspersky
Tags:
Kaspersky
Global Research and Analysis Team
GReAT
WhatsApp
WhatsApp Desktop
WhatsApp Web
Kaspersky Premium
Fareed Radzi
malware
cyber security
Comments
Your comment
Most Important News
Full information is available only to commercial users-subscribers and it is necessary to log in.
Pratite na našem portalu vesti, tendere, investicione projekte, grantove i pravnu regulativu.
Registracija na eKapiji vam omogućava pristup potpunim informacijama i dnevnom biltenu
Naš dnevni ekonomski bilten će stizati na vašu mejl adresu krajem svakog radnog dana. Bilteni su personalizovani prema interesovanjima svakog korisnika zasebno,
uz konsultacije sa našim ekspertima.

Izdanje Srbija
Serbische Ausgabe
Izdanje BiH
Izdanje Crna Gora