WhatsApp Malware Alert: Hackers Hijacking Trusted Accounts To Spread Malicious Files; Here Is How To Stay Safe
Hackers are hijacking WhatsApp accounts to send malicious business documents that, when opened, compromise computers via RMM software. This global campaign affects regions including Asia and South America, masquerading as Windows updates to bypass security. Users are urged to exercise extreme caution with unexpected attachments.
Cybercriminals have launched a sophisticated global malware campaign targeting users of WhatsApp Desktop and WhatsApp Web, according to a report by Kaspersky’s Global Research and Analysis Team (GReAT). The attack uses hijacked WhatsApp accounts to distribute malicious files, allowing hackers to gain full remote access to victims' computers.
WhatsApp Scam Modus Operandi: Exploiting Trust
The campaign relies on social engineering by sending malicious messages from accounts that have already been compromised. Because these messages appear to come from trusted contacts, recipients are significantly more likely to open attachments without suspicion. 'Boss Scam' Alert: MHA Warns Against New Cyber Fraud Targeting CEOs and Executives for Illegal Financial Transfers; Check Details.
-
Disguised Files: Malicious files are masked as routine business documents to avoid detection.
-
Defense Evasion: The malicious code includes hidden text and metadata designed to mimic legitimate Microsoft Windows Update components, aiming to bypass built-in security features.
-
Infection Chain: Once a user opens the file, a silent, multi-stage infection process begins, creating a secret folder to store stolen data and connecting to a hacker-controlled server to retrieve additional malicious components.
-
System Takeover: The final stage involves installing commercial Remote Monitoring and Management (RMM) software, which grants attackers complete control and monitoring capabilities over the victim's system.
Global Reach and Impact
The campaign has an international footprint, with malicious file names localised in English, Portuguese, French, German, and Malay. While major impacts have been observed in European regions, a significant number of victims have been identified across South America and Asia, with the highest concentration of infections reported in Malaysia, followed by Brazil, Singapore, Taiwan, and Vietnam.
Recommended Security Guidelines
-
Exercise Caution: Be wary of unexpected attachments received via WhatsApp, even if they originate from close friends or business associates.
-
Avoid Risky Formats: Never open files with script or executable extensions—such as .vbs, .vbe, .exe, .bat, or .js—unless their legitimacy is verified beyond doubt. WhatsApp Plus Features, How To Subscribe To Meta's INR 79 Service.
-
Stay Alert: Security researcher Fareed Radzi noted that attackers are actively exploiting trust on messaging platforms to execute staged infection chains.
Security researchers have urged users to remain vigilant and follow specific safety measures to protect their systems:
(The above story first appeared on LatestLY on Jun 23, 2026 08:50 PM IST. For more news and updates on politics, world, sports, entertainment and lifestyle, log on to our website latestly.com).