---
title: "WhatsApp phishing attack uses fake business docs to hack PCs"
url: https://daily.dev/posts/whatsapp-phishing-attack-uses-fake-business-docs-to-hack-pcs-yaajoxpkj
source_url: https://www.bleepingcomputer.com/news/security/whatsapp-phishing-attack-uses-fake-business-docs-to-hack-pcs
type: article
source: "BleepingComputer"
published: 2026-06-22T22:45:37.614Z
updated: 2026-06-22T23:26:56.703Z
tags: ["malware", "phishing"]
reading_time: 3
upvotes: 1
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# WhatsApp phishing attack uses fake business docs to hack PCs

**[BleepingComputer](https://daily.dev/sources/bleepingcomputer)** · 3 min read · 1 upvotes · 0 comments

## Summary

An active malware campaign is targeting WhatsApp users across multiple countries by sending obfuscated VBScript files disguised as business and financial documents from compromised contacts. When executed on Windows, the scripts disable UAC protections via Registry modifications and silently install ManageEngine Endpoint Central, a legitimate RMM tool, configured to connect to attacker-controlled servers for remote access. The campaign has been observed in Brazil, India, Mexico, Singapore, the UK, and several other countries. Kaspersky researchers found possible links to Chinese-language infrastructure and overlaps with ValleyRAT and Gh0st RAT activity, though attribution remains uncertain. Users are advised to verify unexpected files through secondary channels and scan all downloads before execution.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.bleepingcomputer.com/news/security/whatsapp-phishing-attack-uses-fake-business-docs-to-hack-pcs>

## Similar posts on daily.dev

- [An unknown actor distributes malicious VBS scripts via WhatsApp](https://daily.dev/posts/an-unknown-actor-distributes-malicious-vbs-scripts-via-whatsapp-uftisbzj3) · Securelist · 1 upvotes · 0 comments
- [Don't open that WhatsApp message, Microsoft warns](https://daily.dev/posts/don-t-open-that-whatsapp-message-microsoft-warns-wbthhnyrz) · The Register · 0 upvotes · 0 comments
- [Self-Propagating Malware Spreading Via WhatsApp, Targets Brazilian Users](https://daily.dev/posts/self-propagating-malware-spreading-via-whatsapp-targets-brazilian-users-enazoyuzo) · Trend Micro · 0 upvotes · 0 comments

---

Tags: [#malware](https://daily.dev/tags/malware), [#phishing](https://daily.dev/tags/phishing)

[View this post on daily.dev](https://daily.dev/posts/whatsapp-phishing-attack-uses-fake-business-docs-to-hack-pcs-yaajoxpkj)
