WhatsApp Desktop, WhatsApp Web Users Targeted Using Malware Campaign, Kaspersky Warns

Kaspersky advises users to remain cautious when receiving unexpected attachments through WhatsApp.

Advertisement
Written by Nithya P Nair, Edited by David Delima | Updated: 23 June 2026 14:25 IST
Highlights
  • Kaspersky discovered new massive campaign spreading malware via WhatsApp
  • Attackers are targeting users through malicious file attachments
  • Attackers use compromised WhatsApp accounts to distribute files

Kaspersky advises users to remain cautious when receiving unexpected attachments through WhatsApp

Photo Credit: Unsplash/Grant Davies

An ongoing malware campaign appears to be hitting WhatsApp users in multiple countries. Cybersecurity firm Kaspersky found that a crimeware actor uses WhatsApp accounts to distribute malicious attachments. The issue has affected users across multiple countries, with the highest number of victims found in Malaysia. Kaspersky researchers state that attackers are using WhatsApp accounts which have been previously compromised to deliver malicious attachments that appear to originate from known contacts. The file names are designed to resemble business documents.

Kaspersky Warns of WhatsApp Malware Campaign

Kaspersky Global Research and Analysis Team (GReAT) discovered a malware distribution campaign targeting users of WhatsApp Desktop and WhatsApp Web. Attackers are targeting users through malicious file attachments sent via direct messages. Kaspersky states that the campaign uses compromised WhatsApp accounts to distribute malicious VBScript files.

Advertisement

The report includes screenshots of WhatsApp messages containing the malicious VBScript file. They show that the attackers have named the malicious files to resemble business documents, and the discovered files are named invoices, bank statements, account statements and debt notices.

"Once opened, they trigger a staged infection chain that silently retrieves and executes additional malicious components from external infrastructure,” said Fareed Radzi, security researcher at Kaspersky GReAT.

Advertisement

Kaspersky Researchers note that File names are in English and other languages, including Portuguese, French, German, and Malay. The VBScript samples also said to include extensive comments and metadata designed to imitate genuine Microsoft Windows Update components. The cybersecurity firm claims that Victims have been identified from countries including Malaysia, Brazil, Singapore, Taiwan, and Vietnam. Malaysia accounts for the highest number of observed infections. The operation appears to be targeting users in Europe and other regions.

When an affected user opens the file, it triggers a scripted sequence on the device. The initial script creates a working directory under C:\Users\Public\Documents\, then retrieves additional script files from external infrastructure and executes them using Windows Script Host. The malware enables remote access to the system through standard administrative capabilities intended for legitimate IT support and management use.

Advertisement

Kaspersky advises users to remain cautious when receiving unexpected attachments through WhatsApp, even when they are coming from known contacts. Users have to be cautious when opening script and executable file types, such as .vbs, .vbe, .exe, .bat, .cmd, .js, and .ps1, unless their legitimacy has been independently verified. Kaspersky also recommended using a strong security solution on all computers and mobile devices.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. This Could Help Apple Reduce Its iPhone 18 Pro Series Manufacturing Costs
  2. Samsung Galaxy S26 Series Gets Up to Rs. 30,500 Discount in Freedom Sale
  3. Here's When the Google Fitbit Air Will Launch in India
  4. Realme 16x 5G Goes on Sale in India With These Offers
  5. OTT Releases This Week: Cocktail 2, Bharat Bhhagya Viddhaata, and More
  6. Vivo's New S50t Vitality Edition Packs a Snapdragon 8s Gen 3 Chipset
  7. iQOO Neo 11 Ultra Will Launch With This Custom MediaTek SoC
  8. Google Pixel 11 vs iPhone 17: Price in India and Specifications Compared
  9. Google Pixel 11 Pro Fold vs Pixel 10 Pro Fold: What's The Difference
  1. Samsung Galaxy S26 FE, Galaxy Tab S12+ and Galaxy A07s Spotted on Google Play Console
  2. Vivo X500 Pro Max Reportedly Bags 3C Certification, Charging Speed Revealed
  3. CD Projekt Red Confirms Layoffs at Project Sirius Witcher Multiplayer Spinoff
  4. Xiaomi’s Next Foldable Leaked With Wider Screen Ahead of Expected September Launch
  5. Metaplanet Denies BTC Liquidation as Bitcoin Falls Below Company's Average Cost
  6. iQOO Neo 11 Ultra Confirmed to Launch With a Custom MediaTek Chipset With New 'Monster' Super Core Engine
  7. Honor Magic 9 Series Launch Confirmed; Launch Date, Camera Details Tipped Online
  8. Apple Reportedly Secures Better Deal for iPhone 18 Pro Series’ OLED Panels; iPhone 18 Leak Hints at New Upgrades
  9. Vivo Y6k Reportedly Spotted on Google Play Console; Could Arrive as Another Rebranded Y-Series Model
  10. BGMI Redeem Codes for August 13 Released: How to Claim Smiling Pal Backpack, Other Free Rewards
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.