Kaspersky

Kaspersky Uncovers Extensive WhatsApp Desktop Malware Campaign

Kaspersky, a global cybersecurity and digital privacy company, has identified a new large-scale malware campaign specifically targeting users of WhatsApp Desktop and WhatsApp Web. The campaign, uncovered by Kaspersky's Global…

June 23, 2026
3 min read

Kaspersky, a global cybersecurity and digital privacy company, has identified a new large-scale malware campaign specifically targeting users of WhatsApp Desktop and WhatsApp Web. The campaign, uncovered by Kaspersky’s Global Research and Analysis Team (GReAT), leverages compromised WhatsApp accounts to distribute malicious files, often disguised as routine business documents.

The operation has impacted users across multiple countries and territories, including Malaysia, Brazil, Singapore, Taiwan, and Vietnam, with Malaysia observing the highest number of reported victims. Analysis of the malicious files revealed the use of multiple languages in file names, suggesting a broad regional focus, particularly across Europe.

Kaspersky: Campaign Mechanics and Social Engineering

The campaign relies on social engineering tactics, utilizing existing contacts of previously compromised WhatsApp accounts to send malicious attachments. This approach significantly increases the likelihood of recipients opening the files due to perceived trust. The files are designed to mimic common business documents such as invoices, bank statements, account statements, payment records, and debt notices.

Kaspersky

File names are localized into various languages, including English, Portuguese, French, German, and Malay, indicating a strategic effort to target diverse linguistic regions. Furthermore, the VBScript samples contain extensive comments and metadata, deliberately crafted to resemble legitimate Microsoft Windows Update components, enhancing their deceptive appearance.

Fareed Radzi, a security researcher at Kaspersky GReAT, noted that “attackers are exploiting trust within messaging platforms by using compromised WhatsApp accounts to deliver malicious attachments that appear to originate from known contacts, making recipients far more inclined to engage with them.” He added that the file names are “carefully disguised as routine business documents, such as invoices and payment notices, and localized across multiple languages to support broad targeting.”

Technical Execution of the Malware

Upon opening the malicious attachment, a multi-stage infection process is initiated on the user’s system. The initial script creates a working directory under `C:\Users\Public\Documents\`. Subsequently, it retrieves additional script files from external infrastructure and executes them using the Windows Script Host. These follow-up scripts perform further system actions and download a compressed archive from the same remote infrastructure. The archive ultimately contains an installation package for remote monitoring and management (RMM) software, granting attackers unauthorized access and control over the compromised system.

The full report detailing this campaign is available on Securelist.com. For more information on the latest cybersecurity threats and industry developments, readers can visit TechnoSports (https://technosports.co.in/).

User Recommendations

Kaspersky GReAT experts advise users to exercise caution and adhere to the following security best practices to mitigate risks associated with such campaigns:

Verify Attachments: Be wary of unexpected attachments received via WhatsApp, even if they appear to originate from known contacts. Always verify the legitimacy of such files before opening them.
Avoid Script and Executable Files: Refrain from opening script and executable file types, including `.vbs`, `.vbe`, `.exe`, `.bat`, `.cmd`, `.js`, and `.ps1`, unless their authenticity has been independently confirmed.
Utilize Security Solutions: Deploy a robust security solution on all computers and mobile devices. Products like Kaspersky Premium (https://www.kaspersky.com/) are designed to detect and prevent such infections.

Follow us on Google News Get real-time updates & exclusive tech coverage
Follow

Leave a Reply

Your email address will not be published. Required fields are marked *