Beware of the Spread of Malware Via WA Desktop: Click the Attachment, Computer Hacked

Malware Spread Via WhatsApp: Warning from Kaspersky
WhatsApp users who frequently use services via WhatsApp Desktop or WhatsApp Web are asked to increase their vigilance. A malware distribution campaign has been discovered by cybersecurity company Kaspersky, which exploits the messaging platform to defraud users and trap victims.
In the latest report from Kaspersky’s Global Research and Analysis Team (GReAT) in June 2026, it was stated that the perpetrator sent a file in the form of VBScript via WhatsApp conversation. This attack has been discovered in several countries, including Brazil, Singapore, Taiwan, Vietnam and Malaysia, which are the regions with the highest number of victims.
Kaspersky also found that the file names used varied across languages. This shows that this campaign is not only targeting the Asian region, but is also starting to spread to a number of countries in Europe.
Leveraging Inter-User Trust
The method used by the perpetrator relies on social engineering techniques. They first took over the victim’s WhatsApp account, then used the account to send malicious files to all saved contacts.
Because the message comes from a known person, such as a friend, relative, or coworker, the recipient is generally unsuspecting. This condition makes the victim’s chances of opening the attached file much greater.
To look more convincing, the perpetrator gives the file a name that resembles a document that is usually received in daily activities. Examples are purchase invoices, banking reports, proof of payment, and debt collection letters. In fact, the file has malicious code inserted. In fact, the code is designed to look like official components of Microsoft Windows updates with fake comments and metadata added to make it harder to recognize as a threat.
Computers Can Be Controlled Remotely
According to Fareed Radzi, Senior Security Researcher at Kaspersky GReAT, this attack relies on psychological manipulation so that victims voluntarily run the malicious file. Once the attachment is opened, the infection process proceeds gradually without displaying any suspicious activity.
The script will first create a hidden directory on the computer, then contact the perpetrator’s server using Windows Script Host to download additional components. The next stage is more dangerous, as the system will download a compressed archive containing remote management and monitoring software.
If installed successfully, the perpetrator can gain administrative access rights to the victim’s computer, thereby potentially controlling the device, monitoring activity, and stealing various important data remotely.
Recommended Steps
To reduce the risk of becoming a victim, Kaspersky urges users to implement a number of preventive measures. First, don’t immediately trust attached files received via WhatsApp, even if they were sent by someone you know. Always check with the sender first via other communication media.
Second, pay attention to the type of file received. Avoid opening files with extensions such as .vbs, .vbe, .exe, .bat, .cmd, .js, or .ps1 before ensuring they are truly safe.
Apart from that, users are also advised to install and regularly update security software on their computers and cellphones so that suspicious activity can be detected early.
Kaspersky reminds us that no matter how strong a messaging application’s encryption system is, the human factor is still the weak point that is most often exploited by cybercriminals. Therefore, caution when receiving and opening attachments remains the primary defense measure to maintain the security of personal data in the digital space.























