{
    "success": true,
    "data": {
        "id": 1823095,
        "msgid": "warning-issued-over-malware-spreading-whatsapp-messages-1782370451",
        "date": "2026-06-25 13:10:00",
        "title": "Warning Issued Over Malware-Spreading WhatsApp Messages",
        "author": "",
        "source": "CNBC",
        "tags": "",
        "topic": "Technology",
        "summary": "Cybersecurity researchers have uncovered a campaign distributing malware through compromised WhatsApp accounts, with victims identified in several countries including Malaysia and Singapore. The attackers send malicious VBScript files disguised as routine business documents from trusted contacts to increase the likelihood of infection. Kaspersky urges users to exercise caution with attachments and avoid opening suspicious file types.",
        "content": "<p>Jakarta, CNBC Indonesia - Users of WhatsApp Web and WhatsApp Desktop\nare being urged to remain vigilant after cybersecurity researchers\ndiscovered malware spreading through direct messages on the platform.\nKaspersky\u2019s Global Research and Analysis Team (GReAT) uncovered the\ncyberattack campaign in June 2026, in which perpetrators used hacked\nWhatsApp accounts to send dangerous VBScript files to the victims\u2019\ncontacts. Kaspersky has recorded victims in several countries and\nregions, including Malaysia, Brazil, Singapore, Taiwan, and Vietnam,\nwith Malaysia having the highest number of identified cases. The use of\nmultiple languages in the file names indicates that the attackers are\nalso targeting users in various other regions, particularly Europe.\nAccording to Kaspersky, the messages containing the malicious\nattachments were sent from contacts already known to the victim. This\nmethod increases the likelihood of the recipient opening the file, as\nthey believe the message comes from a trusted source. \u201cIn this scheme,\nthe attacker exploits trust in messaging platforms by using compromised\nWhatsApp accounts to send malicious attachments that appear to come from\nknown contacts, making recipients more likely to interact with them,\u201d\nsaid Kaspersky GReAT Security Researcher Fareed Radzi in a written\nstatement. The perpetrators disguised the dangerous files as common\neveryday business documents. Kaspersky found examples of file names\nresembling invoices, bank statements, account reports, payment records,\nand debt notices. Furthermore, the file names were crafted in various\nlanguages, including English, Portuguese, French, German, and Malay, to\nreach a broader range of targets. The VBScript samples used were even\nequipped with comments and metadata designed to mimic official Microsoft\nWindows Update components to avoid raising suspicion. Fareed explained\nthat once the file is opened, the malware initiates a multi-stage\ninfection chain. The file silently downloads and executes additional\nmalicious components from an external server controlled by the\nattackers. \u201cThe file names are carefully disguised as routine business\ndocuments, such as invoices and payment notices, and localised in\nmultiple languages to support broad targeting. Once opened, the file\ntriggers a phased infection chain that stealthily retrieves and executes\nadditional malicious components from external infrastructure,\u201d he\nstated. Kaspersky detailed that the initial stage of infection begins\nwhen the script creates a working directory in the C:folder. The malware\nthen downloads an additional script from external infrastructure and\nexecutes it via Windows Script Host. The subsequent script performs\nvarious activities on the victim\u2019s system and downloads a compressed\narchive containing remote monitoring and management software. Once\ninstalled, the malware allows the perpetrator to gain remote access to\nthe victim\u2019s system using administrative capabilities commonly employed\nfor technical support and IT management. To avoid similar attacks,\nKaspersky advises users not to carelessly open attachments received via\nWhatsApp, even if the message appears to come from a known contact.\nUsers are also recommended not to open files with extensions such as\n.vbs, .vbe, .exe, .bat, .cmd, .js, or .ps1 before verifying their\nauthenticity. Additionally, the use of security solutions on computers\nand mobile devices is considered essential to help detect and block\nmalware infection attempts.<\/p>",
        "url": "https:\/\/jawawa.id\/newsitem\/warning-issued-over-malware-spreading-whatsapp-messages-1782370451",
        "image": ""
    },
    "sponsor": "Okusi Associates",
    "sponsor_url": "https:\/\/okusiassociates.com"
}