Signal

WhatsApp phishing campaign uses fake business documents to deploy remote access malware

Evidence first: scan the strongest sources, then decide whether to go deeper.

Published 2026-06-22 10:00 UTCUpdated 2026-06-22 22:42 UTC
rss
malwarephishingremote_accessincident_response
Trend in the last 24h
Current brief openSource links open
This current signal is open on the public brief with summary, metadata, source links, and full evidence. Pro adds compare-over-time, alerts, exports, and workflow.
No card needed for the free brief.
Evidence trail (top sources)
top sources (2 domains)domains are deduped. counts indicate coverage, not truth.
2 top sources shown
limited source diversity in top sources
Overview

A widespread phishing campaign targets WhatsApp users across multiple countries by sending malicious VBScript files disguised as business and financial documents.

Score total
1
Momentum 24h
2
Posts
2
Origins
2
Source types
1
Duplicate ratio
0%
Why now
  • The campaign is currently active and spreading across multiple countries.
  • Targeting of WhatsApp Desktop and Web users exploits popular communication channels.
  • Recent reports show increasing victim counts, especially in Malaysia, indicating escalation.
Why it matters
  • Attackers exploit trusted messaging platforms to spread malware, increasing infection success rates.
  • Use of legitimate RMM software complicates detection and response efforts.
  • The campaign's global reach highlights the need for user vigilance and robust security controls.
LLM analysis
Topic mix: lowPromo risk: lowSource quality: high
Recurring claims
  • WhatsApp users are targeted with phishing messages containing malicious VBScript files disguised as business documents.
  • The VBScript files install legitimate Remote Monitoring and Management (RMM) software to enable remote system access.
How sources frame it
  • BleepingComputer: neutral
  • Securelist (Kaspersky): neutral
All evidence
All evidence
BleepingComputer - WhatsApp phishing attack uses fake business docs to hack PCs
bleepingcomputer.com · bleepingcomputer.com · 2026-06-22 22:42 UTC
Securelist (Kaspersky) - WhatsApp VBScript campaign deploying RMM software
securelist.com · securelist.com · 2026-06-22 10:00 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 2Origin domains: 2Duplicates: -
Showing 2 / 0
Top publishers (this list)
  • bleepingcomputer.com (1)
  • securelist.com (1)
Top origin domains (this list)
  • bleepingcomputer.com (1)
  • securelist.com (1)