HomeSecurityHackers target Windows users via WhatsApp

Hackers target Windows users via WhatsApp

A new, disturbing cyberattack campaign is underway, using WhatsApp as a malware distribution vehicle and targeting Windows in more than a dozen countries. The attack exploits the trust users place in messages from known contacts, disguising malicious files as ordinary financial documents.

Windows via WhatsApp

Security researchers at Securelist discovered the campaign in June 2026 and confirmed that it remains active. Most incidents have been recorded in Malaysia, which accounts for around 80% of total infections, while victims have also been identified in Brazil, India, Mexico, Singapore, the United Kingdom, Spain, Taiwan, Australia, Russia, and Vietnam.

How the attack begins

The campaign relies on compromised WhatsApp. Attackers gain access to real user accounts and then send malicious attachments to all of their contacts. Because the messages appear to come from familiar faces, recipients are much more likely to open the files without a second thought.

See also: Google Ads scam: Fake Node.js installer infects PCs with infostealer

The attachments use VBScript extensions and appear with names like “Financial Reports,” “Debt Statement,” or “Account Statement.” In fact, the cybercriminals have created versions in multiple languages, including Portuguese, French, German, and Malay, proving that the operation is designed from the start for global spread.

The chain of infection leading to a full breach

Once the user opens the file via WhatsApp Desktop or WhatsApp Web, the Windows Script Host. From there, the malicious script starts a series of actions in the background.

First, a hidden folder is created within Public Documents with random names to avoid suspicion. The initial script then downloads additional files from servers controlled by the attackers.

The first attempts to modify User Account Control Windows settings , essentially reducing one of the most important layers of protection for the operating system. The second proceeds to install a fully configured remote administration tool , without any warning appearing on the screen.

Hackers target Windows users via WhatsApp

Why is this particular attack so dangerous?

Unlike classic attacks that install ransomware or data-stealing tools, the new campaign uses legitimate remote administration software. This means that the attacker gains full access to the victim's computer and can operate as if they were physically in front of the system.

See also: ShinyHunters: New breaches reveal new era of cyberattacks

The use of legitimate tools makes detection particularly difficult, as many of the actions performed resemble routine IT support procedures. The attacker can browse files, install additional software, collect personal data , or even use the computer as a staging area for further attacks.

Clues leading to Chinese-speaking operators

Security analysts found several clues pointing to a Chinese-speaking developer group. Many versions of the scripts contained comments and explanations written in simplified Chinese, with references to Windows Update functions and system integrity checks.

Meanwhile, one of the command and control server addresses has previously appeared in cases linked to the ValleyRAT and Gh0st RAT. While there is no definitive proof of a connection, researchers believe the campaign is likely related to Chinese-speaking cybercriminals.

Hackers target Windows users via WhatsApp

Trust in known contacts becomes the new weak point

The case highlights a broader trend in modern cybercrime: attacks are increasingly based on social engineering and the abuse of human trust. Users tend to assume that any files sent by friends, family or colleagues are safe, ignoring the possibility that their accounts have already been compromised.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: AryStinger botnet has infected thousands of D-Link routers

Experts recommend never opening files with the extensions VBS, VBE, EXE, BAT, CMD, JS, or PS1 without prior confirmation from another communication channel. At the same time, keeping Windows security mechanisms active and using modern endpoint protection solutions can significantly reduce the risk of infection from such attacks

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS