New WhatsApp phishing campaign allows remote access from a single business document


  • Kaspersky warns of a WhatsApp phishing campaign that spreads malicious VBScript files disguised as business documents
  • Running them installs ManageEngine Endpoint Central, giving attackers remote access; filenames localized increased global reach
  • Victims span Brazil, India, Mexico, Singapore, UK, Spain, Taiwan, Australia, Russia, Vietnam and Malaysia; compromise method remains unknown

WhatsApp users beware – there is a phishing campaign underway on the platform that seeks to infect your devices with a legitimate but unsolicited endpoint security platform.

Security researchers Kaspersky recently published a new report detailing a campaign that starts with a compromised WhatsApp account. They could not determine how these accounts were breached, but found that they were used to reach out to victims’ contacts and share a VBScript file that was passed off as business or financial documents.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top