Kaspersky: hijacked WhatsApp accounts spread attachments granting remote control

Kaspersky describes an ongoing campaign in which attackers use compromised WhatsApp accounts to send malicious VBScript attachments disguised as invoices, statements, debt notices or other business documents. Opened in WhatsApp Desktop or WhatsApp Web, the script downloads further scripts, attempts to weaken Windows User Account Control prompts, hides files in public folders and silently installs ManageEngine Endpoint Central. That is a legitimate management tool, and it gives the attacker remote access to the machine. The campaign appears broad and opportunistic, with victims across several countries and the highest activity seen in Malaysia.

What this means for your organisation

The message arrives from a contact the recipient knows, and the attachment resembles something the finance team handles daily. Because the installed tool is legitimate software, security products will not necessarily raise an alarm. Where WhatsApp is used for customer contact or between colleagues, it is a channel that sits outside your mail filtering altogether.

Berigo recommends

  • Decide whether WhatsApp is to be used for work, and if so on which devices and under what constraints.
  • Block VBScript execution for ordinary users through group policy or application control.
  • Alert on the installation of remote management tools outside your approved software portfolio.
  • Remind finance and procurement that documents arriving via messaging apps must be verified through another channel.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch