A Familiar WhatsApp Contact Can Send Malware That Takes Remote Control of Your PC

A message from a familiar WhatsApp contact is not automatically safe, particularly when it carries an unexpected attachment. Kaspersky GReAT has identified a campaign targeting WhatsApp Desktop and WhatsApp Web users through accounts that were compromised earlier.

The campaign exploits trust rather than relying on messages from unknown phone numbers. Once a recipient runs the attachment, the infection chain can ultimately give attackers remote control access to the victim’s computer.

Business Files Used as a Disguise

The malicious attachments are VBScript files that can be executed through Windows Script Host. Their names are disguised as routine administrative documents that may appear credible in business conversations or transactions.

Attackers use themes such as invoices, bank reports, payment records, and debt notices. These labels are intended to make recipients less suspicious of an attachment arriving from a known contact.

Fareed Radzi, a security researcher at Kaspersky GReAT, said the attackers also adapted file names for different audiences. “File names are carefully disguised as routine business documents and localized in multiple languages to support broad targeting,” he said.

CategoryCampaign Finding
Affected regionsMalaysia, Brazil, Singapore, Taiwan, Vietnam, and Europe
Highest identified victim countMalaysia
Languages usedEnglish, Portuguese, French, German, and Malay
Attachment disguisesInvoices, bank reports, payment records, and debt notices

Kaspersky GReAT disclosed the campaign in June 2026. Malaysia has recorded the highest number of identified victims so far, while the use of several languages indicates an effort to reach targets across multiple regions.

How the Infection Chain Works

The malware does not install a remote management tool in a single action. After the attachment is opened, the initial script prepares a working directory at C:UsersPublicDocuments for the next stages.

The script then retrieves additional files from external infrastructure using Windows Script Host. A later stage downloads a compressed archive containing an installation package for remote monitoring and management software.

This multi-stage sequence makes the threat more complex than a typical malicious attachment. A victim who executes the file can create an opening for attackers to control the device remotely.

Kaspersky also found extensive metadata in the VBScript samples. The metadata was designed to imitate legitimate Microsoft Windows Update components, making the malicious activity appear more convincing to security systems.

File Extensions That Require Extra Caution

Unexpected attachments should be treated carefully even when they arrive from a colleague, friend, or business contact. Recipients should independently verify the file with the sender before opening anything that was not requested or does not fit the conversation.

Extensions including .vbs, .vbe, .exe, .bat, .cmd, .js, and .ps1 deserve particular attention. Such files should not be opened unless their origin, purpose, and safety are clear.

Real-time protection in security software can help detect and block an infection before it progresses. However, careful handling of attachments remains important because this campaign uses compromised WhatsApp accounts to exploit existing trust.

Related