The WhatsApp phishing campaign using fake business documents shows how attackers are exploiting trust in known contacts rather than relying only on suspicious emails.
The malicious files are sent from compromised WhatsApp accounts and are disguised as financial reports, billing statements, account notices, and other business documents. When a recipient opens the attached VBScript file on a Windows computer, it downloads additional scripts, weakens User Account Control protections, and installs the legitimate ManageEngine Endpoint Central software.
The software is then configured to connect to infrastructure controlled by the attackers, giving them remote administrative access to the victim’s computer. Because a genuine IT management tool is used, the activity may appear legitimate and can be harder to distinguish from normal administration.
The campaign has affected users across several countries, including India. Its use of compromised accounts makes the messages more convincing because the attachment appears to come from an existing contact.
Organizations should warn employees that files received through WhatsApp must be verified through a separate communication channel, even when they come from a colleague, customer, or supplier. Script files such as VBS, JS, BAT, and PowerShell attachments should not be treated as business documents.
Application controls should restrict Windows Script Host and prevent unauthorized remote-management software from being installed. Security teams should also monitor for unexpected registry changes, script execution, new endpoint-management agents, and connections to unfamiliar management servers.
The key lesson is that a trusted sender does not guarantee a trusted attachment. Once an account is compromised, the attacker inherits the credibility of the victim’s contact list, which is considerably more useful than writing another badly spelled phishing email.
An ongoing malware campaign is targeting WhatsApp users in multiple countries with deceptive messages that push VBScript files, leading to remote system access. [...]
Source: WhatsApp phishing attack uses fake business docs to hack PCs via Bleeping Computer — published 22 Jun 2026.
Was this article helpful?
Your feedback helps us improve the knowledge base.