A malware campaign is targeting WhatsApp users in multiple countries by distributing malicious VBScript files through deceptive messages. These files allow for remote system access after an infection chain is initiated by downloading and executing the attachments.
The attacks start with messages sent from compromised accounts containing a heavily obfuscated VBS file, according to cybersecurity company Kaspersky. Kaspersky telemetry data indicates confirmed infections in Australia, Brazil, India, Malaysia, Mexico, Russia, Singapore, Spain, Taiwan, the U.K., and Vietnam. The threat actor employs file names that mimic business and financial documents, making them appear to come from the victim's contacts whose accounts have been compromised. The malicious files are named to resemble financial reports, billing statements, and account notices, with filenames localized in multiple languages.
Kaspersky stated, "Based on evidence collected from multiple victims through social media reports and submitted samples, we can conclude that the threat actor had gained access to several WhatsApp accounts and used them to distribute the malicious VBScript files to contacts on the compromised users' contact lists." The firm also said, "At the time of writing, the exact method used to compromise these WhatsApp accounts remains unknown." If a victim downloads and opens the file on Windows, the VBScript retrieves two additional scripts from the attacker's infrastructure. These scripts disable User Account Control protections through Registry modifications and then download a ZIP archive containing the ManageEngine Endpoint Central program.
The software is silently installed in the background and configured to connect to attacker-controlled management servers. This configuration provides attackers with remote administration access to the victim's computer. Kaspersky does not attribute the attacks to a specific threat actor. Researchers found indications of Chinese language usage and infrastructure overlap with IP addresses previously linked to ValleyRAT and Gh0st RAT activity. ManageEngine Endpoint Central is software used by IT administrators to manage systems from a centralized dashboard.
forum Comments (0)
No comments yet. Be the first to comment.