WhatsApp phishing attack uses fake business docs to hack PCs
A global WhatsApp phishing campaign delivers obfuscated VBScript files masquerading as business documents to compromised contacts, prompting recipients to download a ZIP that installs ManageEngine Endpoint Central for remote access. The infection chain disables UAC and grants attackers control of the victim’s PC via Windows Script Host; the campaign has spread across Brazil, India, Mexico, Singapore, the UK, Spain, Taiwan, Australia, Russia, Vietnam, and Malaysia. Attribution is uncertain, with signs of Chinese-language usage and overlaps with ValleyRAT/Gh0st RAT infrastructure. Users should verify messages from contacts through alternate channels and scan all attachments before opening.

WhatsApp Phishing Attack Uses Fake Business Documents to Hack PCs
OverviewAn ongoing malware campaign targets WhatsApp users across several countries by sending messages that appear to come from trusted contacts. The messages carry a heavily obfuscated VBScript file with filenames designed to resemble financial reports, billing statements, or account notices. When opened, these attachments trigger a multi-stage infection that culminates in the silent installation of a legitimate management utility, enabling remote control of the victim’s machine.
Attack Narrative
- The threat actor leverages compromised WhatsApp accounts to distribute malicious VBScript files to the infected user’s contact list.
- File names and multilingual localizations are crafted to imitate legitimate business documents, increasing the probability the recipient will open them.
- The campaign’s reach is global, with reported activity in Brazil, India, Mexico, Singapore, the United Kingdom, Spain, Taiwan, Australia, Russia, Vietnam, and Malaysia.
- The initial payload is an obfuscated VBScript that, when executed, downloads two additional scripts from the attacker’s infrastructure and proceeds to disable common security controls through Registry edits.
Infection Chain and Technical Details
- Upon execution, the VBScript contacts the attacker’s servers to fetch two supplementary scripts.
- The downloaded scripts perform Registry modifications that suppress User Account Control (UAC), lowering the barrier for further actions.
- A ZIP archive containing the ManageEngine Endpoint Central program is downloaded and silently installed in the background.
- Once installed, the software connects to attacker-controlled management servers, providing remote administration capabilities over the compromised host.
- The method of delivery can differ depending on the client used: when the initial VBScript is delivered via WhatsApp Web, it typically needs to be downloaded, whereas opening it in the WhatsApp Desktop client can allow direct execution through Windows Script Host (wscript.exe).
Global Reach and Language Clues
- While there is no definitive attribution to a single threat actor, researchers note Chinese language usage in the campaign and infrastructure overlaps with previously observed ValleyRAT and Gh0st RAT activities.
- The broad geographic footprint underscores a sophisticated, globally distributed operation designed to maximize infection opportunities through trusted social channels.
Content and Indicators
- The malicious messages are designed to resemble legitimate financial communications, including documents labeled as reports, billing statements, and account notices.
- Filenames are crafted to be attention-grabbing and credible, with localization to multiple languages to appeal to recipients in different regions.
- Visual samples of the messages and the general attack layout have been circulated by security researchers to illustrate the deception strategy, reinforcing the risk posed by trusted-contact delivery.
Attribution and Uncertainties
- Researchers emphasize that, at the time of reporting, there is insufficient evidence to assign the campaign to a specific, named threat actor with high confidence.
- The combination of language usage, overlapping infrastructure with known tools, and the global reach all contribute to the complexity of forming a definitive attribution in this case.
Implications for Security Operations
- The campaign demonstrates how trusted social channels can serve as effective delivery mechanisms for malware, enabling rapid spread through personal networks.
- The use of VBScript, obfuscation, and a multi-stage download followed by silent installation highlights the importance of layered detection that can identify script-based downloaders and unusual Registry modifications.
- The combination of compromised messaging accounts and credible-looking documents creates a high-confidence deception vector that can bypass initial user skepticism.
Visual and Sample Materials
- Security researchers have published images of the malicious messages and samples of the deceptive filenames used in the campaign.
- Screenshots and sample messages illustrate the level of realism sought by the operators and the risk of interaction for unsuspecting users.
Final Observations
- The campaign exemplifies a growing trend in which remote management tools are leveraged for post-compromise control, elevating the stakes for endpoint security teams.
- The blend of social engineering, compromised accounts, and server-backed script delivery creates a multifaceted threat that requires vigilance across messaging platforms, email, and enterprise management ecosystems.
Notes
- The information above consolidates findings from multiple security researchers who observed the operation, including analyses of the VBScript delivery mechanism, the UAC-disabling steps, and the subsequent deployment of a legitimate remote administration application.


