The images in this article were generated with artificial intelligence. How we publish
A malicious campaign spread by WhatsApp is using camouflaged VBScript files as invoices and financial documents to deliver persistent remote access to Windows equipment: when you open the file, the VBS download more scripts, disable UAC protections by changing the Register and hides the installation of a legitimate remote management tool, ManageEngine Endpoint Central, which is configured to connect to servers controlled by the attackers.
Kaspersky researchers have documented that the messages come from previously committed contact accounts, and that the file names are located in several languages to increase the trap. The technical report of Kaspersky for indicators and samples is available at: https: / / sequrelist.com / Whatsapp-vbs-rmm-campaign / 120290 /. This technique combines social engineering with the abuse of legitimate software, a classic tactic to evade detection: by using a product known to administrators, attackers reduce alarms and get real remote control over the victim machine.

A critical point from which we must all learn is that the means of delivery matters: when the file is opened in WhatsApp Desktop can be run directly using Windows Script Host (wscript.exe), while in WhatsApp Web the user must first download it. This difference increases the risk for users who keep the desktop application open and run files without checking them.
The implications are serious for personal users and organizations. For a company, the unauthorized installation of a remote management agent can allow data exfiltration, lateral movement and future deployment of more harmful loads. For domestic users, it represents the loss of control of devices and exposure of sensitive credentials and documents.
Recommended immediate action: do not open .vbs files or run scripts received by messaging; verify any unexpected shipment with the person sending it on a different channel (called or SMS); and scan any downloaded file with an updated antivirus before running it. To protect workstations, consider disabling Windows Script Host by means of the registration key (e.g. by adjusting HKLM\\ Software\\ Microsoft\\ Windows Script Host\\ Settings\\ Enable to 0) or by group policies, and blocking the execution of wscript.exe if not required.
If you suspect that a team was engaged, isolate it from the network, ask your IT team to review services and processes for remote management agents (e.g. ManageEngine / Endpoint Central), review the Register for Policy Changes of UAC and review scheduled tasks and outgoing connections to unknown servers. Do a complete scanning with detection / EDR tools and restore local and administrator credentials if the intrusion is confirmed.
At the organizational level, more stringent policies on remote management software should be applied: to restrict the installation and management of tools such as Endpoint Central to authenticated servers and accounts, require strong authentication, review certificates and whitelists of management servers, and monitor network telemetry for connections to unapproved destinations. Official product information is available at https: / / www.manageengine.com / products / endpoint-central /.

To reduce the risk that legitimate WhatsApp accounts will be used as attack vectors, users should close remote sessions, activate verification in two steps in WhatsApp and review linked devices from the application configuration. WhatsApp publishes safety recommendations in https: / / www.Whatsapp.com / security.
Finally, it is important for security teams to share indicators and correlate events with suppliers and response communities: this campaign is already global in scope and has affected multiple countries, so collaboration can accelerate detection and mitigation. Keep copies of evidence, record associated times and domains / PIs and, if appropriate, raise the incident to CERT / CISO for coordinated actions.
Practical summary: do not open .vbs received by messaging, check other ways for unexpected shipments, update and use antivirus / EDR, disable WSH if not necessary and immediately review any new installation of remote administration agents. Prevention and verification are the most effective barriers to such campaigns.
Related
More news on the same subject.

Anonymous MousKIT phishing platform identified to remove Activation Lock on iPhone and iPad
Cybersecurity researchers have documented a phishing platform as a service aimed at eliminating the protection of Activation Lock from stolen iPhones and iPads, combining forged...

United States U.S. imposes sanctions on Iranian networks linked to MOIS and Mabna in the Economic Outcast operation
The U.S. Treasury Department has launched a new round of financial sanctions against networks linked to Iran, in a campaign that the U.S. authorities describe as a coordinated e...

NemoClaw operating chain exposes Olama to unauthenticated access and alters chat templates
What has happened (confirmed facts): Oasis Security researchers have published a report describing a chain of exploitation against the NemoClaw configuration that can allow a we...

CISA adds CVE-2026-21962 to KEV by remote operation in Oracle HTTP Server and WebLogic
The United States Agency for Cybersecurity and Infrastructure (CISA) has included in its catalogue Known Exploited Vulnerabilities (KEV) the critical failure traced as CVE-2026-...

IA in code generation accelerates OSS dependencies and generates security mediation debt
A recent seminar organized by ActiveState and a survey of 300 security and development leaders in companies in different sectors confirms something that many teams already notic...

They identify WordlistLoader and SynkLoader, intermediate loaders linked to access brokers for
Cybersecurity researchers have identified two new malware families - called WordlistLoader and SynkLoader - used as intermediate stages to deploy later loads and, according to p...

TikTok will pay 400 million for COPPA; 100 M subject to annulment of decree Musical.ly
The U.S. Department of Justice. United States announced payment of $400 million by TikTok to resolve a 2024 lawsuit that accused the platform - owned by ByteDance - of violating...