Overview
- India’s cybersecurity agency CERT-In issued an advisory on June 25 warning that a large-scale campaign is delivering malicious Visual Basic Script (VBScript) files through WhatsApp Web and Desktop messages.
- The attackers use previously compromised WhatsApp accounts so files arrive from trusted contacts and increase the chance victims will open the attachments.
- Kaspersky’s technical analysis found the VBScript is highly obfuscated and can run a multi-stage chain that disables protections and installs ManageEngine Endpoint Central agents to give persistent, high‑privilege remote access.
- CERT-In tells users not to open unexpected attachments even from friends, to verify suspicious files by calling or messaging the sender separately, and to keep software, user-account controls, and antivirus up to date.
- The campaign is still active in multiple countries, public attribution remains low confidence, and the advisory follows CERT-In’s broader push to tighten OEM cybersecurity requirements earlier in June.