This is the type of file that you should not open if it comes to you via WhatsApp and you do not want your PC to become infected.

A new malware campaign is using WhatsApp to infect computers with Windows through files that appear to be work documents, invoices or financial notices, but end up allowing remote access to the system. According to the cybersecurity firm Kasperskyattackers do not use a common format, such as PDF either wordsbut files of type VBSwhich in Windows can execute instructions automatically if the user opens them.

VBS is the abbreviation of VBScripta Microsoft scripting language that has been used for years to automate tasks in Windows. In administration environments it can be used to launch processes, modify configurations or execute repetitive actions without user intervention. That same capacity makes it dangerous when it arrives via WhatsApp disguised as a business document.

According to Kaspersky, attackers are sending these files from previously compromised WhatsApp accounts. That makes the deception more credible, because the message comes from a real contact of the victim. The file names imitate common documents in the work environment, such as financial reports, invoices, statements or account notices. Furthermore, they are adapted to several languageswhich reinforces the idea that the campaign has international reach.

‘From evidence collected from multiple victims through social media reports and submitted samples, we can conclude that The malicious actor had gained access to multiple WhatsApp accounts and used them to distribute the malicious VBScript files to contacts in the compromised users’ contact lists.‘, explains Kaspersky.

‘At the time of writing this, The exact method used to compromise these WhatsApp accounts is unknown.‘.

Infection via WhatsApp Web and WhatsApp for Windows

The campaign has been detected in several countries, including Spain, United Kingdom, Brazil, India, Mexico, Singapore, Taiwan, Australia, Russia, Vietnam and Malaysia. The attack affects Windows and not other operating systems because it depends on components of the Microsoft system. When the victim opens the VBS file on a PC, it comes into play Windows Script Hostthe tool that allows you to execute this type of scripts. On a mobile, that file cannot be opened, but on a Windows computer it can start the infection.

Consequently, the threat can come in two ways, but with a difference. In WhatsApp Webthe file must be downloaded before opening it. In the application of WhatsApp for WindowsKaspersky warns that the file can be executed directly using wscript.exethe process associated with Windows Script Host. In both cases, The infection begins when the user opens the supposed document.

Once executed, the VBScript file downloads other scripts from the attackers’ infrastructure. Then modify the Windows registry to disable protections UACthe user account control system that warns you before making sensitive changes to your computer. Next download a file ZIP with ManageEngine Endpoint Centrala legitimate tool used by IT administrators to manage computers from a centralized dashboard. Attackers install it silently and configure it to connect to servers under your control. The result is that they obtain remote administration access to the victim’s computer.

Kaspersky does not attribute the campaign to a specific group. Its researchers have found signs of use of chinese language and infrastructure overlaps with IP addresses previously associated with hacker groups ValleyRAT and Gh0st RATbut they do not consider that there is enough evidence to make a solid attribution.

Kaspersky recommends that users, if they receive a file with a .vbs extension via WhatsApp, do not open it, even if it comes from a known contact. The prudent thing to do is to ask another way if you have really sent it. It is also advisable to distrust any supposed working document that does not have a usual length and scan downloaded files with an updated antivirus before running them.