MalwareBleeping Computer
8.0 — CRITICAL
WhatsApp phishing attack uses fake business docs to hack PCs
An ongoing malware campaign is targeting WhatsApp users in multiple countries with deceptive messages that push VBScript files, leading to remote system access. [...]
🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview
A phishing campaign is targeting WhatsApp users with malicious VBScript files, leading to remote system access via the legitimate ManageEngine Endpoint Central software. The attack uses compromised accounts and localized filenames to trick victims into opening the files.
⚙️Technical Details
Affected Systems
Windows
Attack Vectors
WhatsApp messages with obfuscated VBS filesCompromised WhatsApp accountsDownloaded VBScript files
💥Impact Assessment
Severity: high
Who Is at Risk
WhatsApp users in multiple countries
🛡️Recommended Actions
1Treat files sent by contacts with caution and verify them through secondary means
2Scan all downloaded files with an up-to-date antivirus before executing them
3Monitor WhatsApp accounts for suspicious activity
📦Affected Products
WhatsAppManageEngine Endpoint Central
Read the full article
This is a curated summary. The complete article is available at Bleeping Computer.
