Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
WhatsApp Attack Uses Fake Files to Deploy RMM Software

WhatsApp Attack Uses Fake Files to Deploy RMM Software

Posted on June 23, 2026 By CWS

In a recent cyber threat campaign, WhatsApp users are being targeted with malicious Visual Basic Script (VBScript) files disguised as legitimate documents. This operation is aimed at installing genuine Remote Monitoring and Management (RMM) software on victims’ systems, raising alarms in the cybersecurity community.

Global Targeting of WhatsApp Users

According to Kaspersky’s findings, this campaign affects users of WhatsApp Desktop and Web in various countries, including Malaysia, Brazil, India, and others. The highest number of victims is reported in Malaysia. The attackers use deceptive file names that appear to be business or financial documents to trick recipients into downloading and running the files.

Security expert Fareed Radzi has noted that the VBScript initiates a multi-step infection process that ends with the installation of RMM software, granting remote access to the attackers. The exact method of how the attackers gain control over WhatsApp accounts remains uncertain.

Deceptive Techniques and Obfuscation

The VBScript files are heavily obfuscated, camouflaged as harmless documents with names like “Financial Reports.vbs” or “Account Statement.vbs.” These files also appear in multiple languages, showcasing the global reach of the threat. Kaspersky highlights that the scripts contain metadata mimicking legitimate Microsoft components, with notes in Chinese relating to system integrity and update functionalities.

Execution of the VBScript is done through “WScript.exe,” which then retrieves additional components for subsequent attack stages. The infection process varies slightly depending on whether the victim uses WhatsApp Web or Desktop, with distinct methods of execution and file handling in each scenario.

Potential Threats and User Precautions

The ultimate goal of the VBScript is to download further scripts aimed at altering Windows User Account Control (UAC) settings and deploying a ZIP file with the ManageEngine RMM Central installation package. While the attackers remain unidentified, Kaspersky has found infrastructure connections to previous Gh0st RAT and ValleyRAT activities.

Users are advised to exercise caution when receiving unexpected documents through WhatsApp, even those seemingly from known contacts. It’s crucial to verify the authenticity of file types such as VBS, EXE, and others before opening them to avoid potential security risks.

As this threat continues to evolve, maintaining vigilance and adopting robust cybersecurity practices are essential for protecting sensitive information and systems from unauthorized access.

The Hacker News Tags:cyber threat, Cybersecurity, Kaspersky, Malware, Phishing, remote access, RMM software, social engineering, VBScript, WhatsApp

Post navigation

Previous Post: Xsolis Data Breach Impacts 1.4 Million People
Next Post: London Hydro Investigates Customer Data Breach

Related Posts

Operation Endgame Dismantles Rhadamanthys, Venom RAT, and Elysium Botnet in Global Crackdown Operation Endgame Dismantles Rhadamanthys, Venom RAT, and Elysium Botnet in Global Crackdown The Hacker News
Google Identifies Three New Russian Malware Families Created by COLDRIVER Hackers Google Identifies Three New Russian Malware Families Created by COLDRIVER Hackers The Hacker News
Key Capabilities Security Leaders Need to Know Key Capabilities Security Leaders Need to Know The Hacker News
Rise of AI-Powered Cyber Threats Shifts Security Landscape Rise of AI-Powered Cyber Threats Shifts Security Landscape The Hacker News
Cisco Patches CVE-2025-20188 (10.0 CVSS) in IOS XE That Enables Root Exploits via JWT Cisco Patches CVE-2025-20188 (10.0 CVSS) in IOS XE That Enables Root Exploits via JWT The Hacker News
How to Protect the Invisible Identity Access How to Protect the Invisible Identity Access The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Anthropic Alleges Alibaba’s Unauthorized Access to AI Models
  • Mass Exploit Targets Laravel Livewire Apps for Credential Theft
  • Exploit Released for Microsoft Exchange Vulnerability
  • Malicious App on Google Play Poses Serious Security Threat
  • Cyber Attack Uses Fake Microsoft Teams Alerts to Breach Systems

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Anthropic Alleges Alibaba’s Unauthorized Access to AI Models
  • Mass Exploit Targets Laravel Livewire Apps for Credential Theft
  • Exploit Released for Microsoft Exchange Vulnerability
  • Malicious App on Google Play Poses Serious Security Threat
  • Cyber Attack Uses Fake Microsoft Teams Alerts to Breach Systems

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark