A new, disturbing cyberattack campaign is underway, using WhatsApp as a malware distribution vehicle and targeting Windows in more than a dozen countries. The attack exploits the trust users place in messages from known contacts, disguising malicious files as ordinary financial documents.

Security researchers at Securelist discovered the campaign in June 2026 and confirmed that it remains active. Most incidents have been recorded in Malaysia, which accounts for around 80% of total infections, while victims have also been identified in Brazil, India, Mexico, Singapore, the United Kingdom, Spain, Taiwan, Australia, Russia, and Vietnam.
How the attack begins
The campaign relies on compromised WhatsApp. Attackers gain access to real user accounts and then send malicious attachments to all of their contacts. Because the messages appear to come from familiar faces, recipients are much more likely to open the files without a second thought.
See also: Google Ads scam: Fake Node.js installer infects PCs with infostealer
The attachments use VBScript extensions and appear with names like “Financial Reports,” “Debt Statement,” or “Account Statement.” In fact, the cybercriminals have created versions in multiple languages, including Portuguese, French, German, and Malay, proving that the operation is designed from the start for global spread.
The chain of infection leading to a full breach
Once the user opens the file via WhatsApp Desktop or WhatsApp Web, the Windows Script Host. From there, the malicious script starts a series of actions in the background.
First, a hidden folder is created within Public Documents with random names to avoid suspicion. The initial script then downloads additional files from servers controlled by the attackers.
The first attempts to modify User Account Control Windows settings , essentially reducing one of the most important layers of protection for the operating system. The second proceeds to install a fully configured remote administration tool , without any warning appearing on the screen.

Why is this particular attack so dangerous?
Unlike classic attacks that install ransomware or data-stealing tools, the new campaign uses legitimate remote administration software. This means that the attacker gains full access to the victim's computer and can operate as if they were physically in front of the system.
See also: ShinyHunters: New breaches reveal new era of cyberattacks
The use of legitimate tools makes detection particularly difficult, as many of the actions performed resemble routine IT support procedures. The attacker can browse files, install additional software, collect personal data , or even use the computer as a staging area for further attacks.
Clues leading to Chinese-speaking operators
Security analysts found several clues pointing to a Chinese-speaking developer group. Many versions of the scripts contained comments and explanations written in simplified Chinese, with references to Windows Update functions and system integrity checks.
Meanwhile, one of the command and control server addresses has previously appeared in cases linked to the ValleyRAT and Gh0st RAT. While there is no definitive proof of a connection, researchers believe the campaign is likely related to Chinese-speaking cybercriminals.

Trust in known contacts becomes the new weak point
The case highlights a broader trend in modern cybercrime: attacks are increasingly based on social engineering and the abuse of human trust. Users tend to assume that any files sent by friends, family or colleagues are safe, ignoring the possibility that their accounts have already been compromised.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: AryStinger botnet has infected thousands of D-Link routers
Experts recommend never opening files with the extensions VBS, VBE, EXE, BAT, CMD, JS, or PS1 without prior confirmation from another communication channel. At the same time, keeping Windows security mechanisms active and using modern endpoint protection solutions can significantly reduce the risk of infection from such attacks
