WhatsApp Phishing Campaign Spreads Malware via Fake Business Docs Globally
Executive Briefing
- Targets WhatsApp users across 11 countries using compromised contacts to deliver obfuscated VBScript files
- Executes infection chain that silently installs ManageEngine Endpoint Central, granting attackers remote system access
- Disables Windows UAC protections via Registry modifications to avoid detection during installation
- Researchers identify Chinese language artifacts and infrastructure links to ValleyRAT and Gh0st RAT activity
- Users advised to verify all file attachments through secondary channels and scan downloads before opening
Sponsored