Active Global Malware Campaign Abusing Compromised WhatsApp Accounts to Distribute Malicious VBScript FilesAdd Your Heading Text Here
| Severity | HIGH |
| Threat Category | Malware / Social Engineering / Account Compromise |
| Affected Platforms | WhatsApp Desktop, WhatsApp Web (Windows systems) |
| CVE Reference | N/A (Exploits trust, not software vulnerability) |
| CVSS | N/A |
1. Overview
The Bhutan Computer Incident Response Team (BtCIRT) is issuing this advisory to alert government agencies, businesses, and the general public in Bhutan to an active, large-scale malware campaign spreading through WhatsApp Desktop and WhatsApp Web on Windows systems. Rather than exploiting technical software bugs, this campaign manipulates the trusted contact relationship between users, allowing threat actors to distribute malicious scripts under the guise of legitimate business correspondence.
This security advisory is established upon corroborated threat intelligence and reporting from multiple leading international bodies:
Kaspersky’s Global Research and Analysis Team (GReAT) — First disclosed this active campaign through highly detailed original technical research published on Securelist in June 2026, outlining the delivery of VBScript payloads.
MyCERT (Malaysia Computer Emergency Response Team) — Released Advisory MA-1464.062026 (dated June 22, 2026) confirming active targeting against Malaysian WhatsApp users.
CERT-In (Indian Computer Emergency Response Team) — Issued a formal public advisory (dated June 25, 2026) warning of the rapid distribution of this VBScript malware targeting WhatsApp Web/Desktop platforms.
The core threat of this campaign lies in its exploit vector: rather than targeting a network port or unpatched operating system code, the malware propagates by hijacking active accounts and pushing malicious VBScript (.vbs) files directly to the victim’s contacts. This abuse of existing personal and professional trust guarantees an exceptionally high file-open rate, leading to rapid lateral expansion.
2. Who is Affected.
At the time of issuing this advisory, BtCIRT has not received any confirmed local reports of compromise or active malicious script deployment within Bhutan. Nonetheless, the threat level is assessed as immediate and extreme for both corporate networks and private individuals because:
WhatsApp Web and WhatsApp Desktop are heavily utilized across Bhutanese government offices, commercial enterprises, and by individual citizens for daily operations and personal chat.
The propagation method relies entirely on the natural social graph of trusted contacts, meaning a single compromised account can rapidly infect multiple downstream systems in Bhutan without warning.
The attack targeting mechanism does not respect geographic or administrative boundaries; any Windows system running WhatsApp Desktop or accessing WhatsApp via a browser is fully vulnerable if the user executes the file.
3. How the Attack Works
The execution cycle of the attack progresses systematically from account hijacking to a complete host compromise, outlined below:
▪ Stage 1 — Account Takeover:
The threat actor first gains unauthorized access to a victim’s active WhatsApp account. This is typically accomplished through techniques such as session hijacking or credential theft, though the exact initial entry method remains under study by global security researchers.
▪ Stage 2 — Trusted Delivery:
Once in control of the hijacked account, the attacker sends a malicious file attachment to the victim’s existing contact list (friends, family, and colleagues). Crucially, the attacker sends the file with no accompanying text message, relying on the pre-existing relationship to prompt the recipient to download and open the file without suspicion.
▪ Stage 3 — Disguised Lure:
The file sent is a VBScript file (.vbs) carefully disguised as a routine business or financial document. Typical names used in active campaigns include ‘Financial Reports’, ‘Account Statement’, ‘Outstanding Payment List’, or ‘Debt Statement’ to entice the victim into opening them immediately.
▪ Stage 4 — Multi-Stage Infection:
Upon execution, the script runs in the background using the native Windows Script Host (wscript.exe). It silently establishes a hidden working folder and contacts an attacker-controlled Command and Control (C2) server to download additional malicious script components. The script’s code comments are deceptively structured to mimic legitimate Microsoft Windows Update components to evade local security audits and system administrator detection.
▪ Stage 5 — Remote Access Installed:
The final execution stage installs a legitimate Remote Monitoring and Management (RMM) agent. Specifically, Kaspersky’s threat intelligence identified the abuse of ManageEngine Endpoint Central in this campaign. This installs a functional backdoor on the machine, giving the remote threat actor full, interactive access to the operating system.
Impact: Once full RMM control is established, the remote attacker has active administrative access to the victim’s local machine. This enables malicious actors to harvest browser-saved credentials, record keystrokes, exfiltrate confidential files, deploy ransomware, or move laterally within a connected corporate or government intranet.
4. Indicators to Watch For
Security teams and end-users must look for the following administrative and behavioral indicators to detect potential compromise:
Receipt of an unexpected file attachment via WhatsApp from a known, trusted contact, particularly with no accompanying message text or explanation.
Files delivered over chat that feature financial or business terms (e.g., invoices, outstanding payments) but end in script extensions such as .vbs, .vbe, .js, .wsf, .hta, .bat, .cmd, or .ps1.
The unexplained installation, running, or registry registration of unfamiliar remote monitoring agents (specifically ManageEngine Endpoint Central) on end-user machines.
Unfamiliar devices listed under the WhatsApp application’s ‘Linked Devices’ menu, indicating potential session hijacking.
5. Recommendations
For organizations and government offices:
Circulate this advisory immediately to all personnel to establish a company-wide ‘verify before you open’ policy for all incoming messaging-app attachments.
Restrict or strictly monitor the execution of Windows Script Host (wscript.exe / cscript.exe) on administrative and general end-user workstations where not required for routine administrative tasks.
Audit active endpoints for the unauthorized installation of Remote Monitoring and Management (RMM) utilities or agents.
Ensure corporate WhatsApp Desktop or browser-based WhatsApp utilization is actively covered and analyzed by Endpoint Detection and Response (EDR) tooling.
Review and enforce strict User Account Control (UAC) elevation policies, as this malware is observed trying to actively bypass and weaken elevation notifications.
For individuals:
Never open file attachments received on WhatsApp, even from trusted contacts, without verifying through a secondary, out-of-band communication channel (like a voice call or direct text) that the sender actually intended to transmit the file.
Never run or double-click script file types (including .vbs, .js, .wsf, .bat) received through social media or chat applications.
Regularly audit the ‘Linked Devices’ menu inside your mobile WhatsApp settings. Terminate any active sessions that you do not explicitly recognize.
Enable two-factor authentication (2FA) inside your WhatsApp account settings to provide an extra layer of protection against hijacking attempts.
Ensure your Windows operating system, internet browsers, and WhatsApp client are fully updated, and verify that your local antivirus protection is active.
6. Reporting
If you suspect your workstation or personal device has been compromised by this threat, or if you identify a suspicious file matching the described behaviors, please isolate the system from your network and contact BtCIRT immediately at cirt@btcirt.bt.
7. Sources and Reference
1. CERT-In (Indian Computer Emergency Response Team) Advisory (June 25, 2026): “Active malware campaign targeting WhatsApp Web and Desktop users” — https://the420.in/cert-in-whatsapp-desktop-web-malware-advisory-hacked-accounts/
2. MyCERT (Malaysia Computer Emergency Response Team) Advisory MA-1464.062026 (June 22, 2026): “Malware Campaign Delivering Malicious VBScript via WhatsApp Desktop” — https://mycert.org.my/portal/advisory?id=MA-1464.062026
3. Kaspersky GReAT / Securelist Threat Intelligence Disclosures (June 2026): “An unknown actor distributes malicious VBS scripts via WhatsApp” — https://securelist.com/whatsapp-vbs-rmm-campaign/120290/
This advisory will be updated if BtCIRT receives confirmed reports of this campaign/vulnerability affecting users or systems within Bhutan, or as further technical detail becomes available from the international community.
