Particle.news

CERT-In Warns of Large Malware Campaign Targeting WhatsApp Web and Desktop

Kaspersky research shows attackers send heavily obfuscated VBScript from compromised accounts that can install legitimate endpoint-management software to create covert remote access.

Overview

  • India’s cybersecurity agency CERT-In issued an advisory on June 25 warning that a large-scale campaign is delivering malicious Visual Basic Script (VBScript) files through WhatsApp Web and Desktop messages.
  • The attackers use previously compromised WhatsApp accounts so files arrive from trusted contacts and increase the chance victims will open the attachments.
  • Kaspersky’s technical analysis found the VBScript is highly obfuscated and can run a multi-stage chain that disables protections and installs ManageEngine Endpoint Central agents to give persistent, high‑privilege remote access.
  • CERT-In tells users not to open unexpected attachments even from friends, to verify suspicious files by calling or messaging the sender separately, and to keep software, user-account controls, and antivirus up to date.
  • The campaign is still active in multiple countries, public attribution remains low confidence, and the advisory follows CERT-In’s broader push to tighten OEM cybersecurity requirements earlier in June.