WhatsApp users are warned of a malware campaign that is spreading, in which cybercriminals are using fake business and financial documents to infect Windows devices.
The cybersecurity company Quick Heal Technologies has been warning users about the campaign, which it said was targeting finance team members, senior executives, chartered accountants and business users. The attackers are using compromised WhatsApp accounts to send malicious files to the victims’ contacts. Since the messages seem to come from someone the recipient already knows, the files may be more trustworthy than genuine scam messages.
The warning is particularly relevant for people who use WhatsApp Web or WhatsApp Desktop for work. A seemingly routine document that is sent through a familiar chat could cause a malware infection if opened or executed.
How does the WhatsApp malware attack work?
Some security researchers have seen attackers using compromised WhatsApp accounts as a distribution channel. Once an account has been compromised, the malicious attachments can be sent to people already in the app’s contact list.
This makes the scam harder to identify. Users can see a message from a colleague, client, business associate, or even a friend and assume the attachment is legitimate.
The files are designed to look like regular business papers. Researchers have found names that look like financial reports, account statements, debt statements, invoices and other routine paperwork. The attackers have even used different languages, indicating the attackers want to reach people in multiple countries.
CERT-In, India’s cybersecurity agency, had warned of a WhatsApp malware campaign involving malicious Visual Basic Script (VBScript) files. The agency said the campaign primarily targeted WhatsApp Desktop and WhatsApp Web users.
Some of the attackers were using compromised accounts to distribute the malicious attachments directly to existing contacts. The files were disguised as routine business documents to increase the chances that recipients would download and open them.
The same campaign has also been observed in India, Malaysia, Brazil, Mexico, Singapore, the UK, Spain, Taiwan, Australia and Russia. Malaysian infections represented the largest share of infections in the campaign they examined, security researchers said.
What happens if you open the malicious file?
The danger begins when a user downloads and executes the malicious attachment on a Windows computer.
The researchers discovered that the VBScript can initiate a multi-stage infection process. It can download additional malicious components from attacker-controlled servers and eventually install legitimate remote-management software that can be abused by attackers to maintain access to the infected computer.
This kind of attack can be particularly dangerous as the final software involved may be legitimate. So rather than just infecting a system with a virus, attackers can use legitimate remote-management tools to control a compromised machine.
A successful infection could give attackers the ability to access the computer remotely. Depending on what else is installed or stored on the device, that could be sensitive business information, personal files, and other data.
The campaign also illustrates why you should not automatically trust an attachment just because it’s from a known WhatsApp contact. A familiar account might have already been compromised.
How can WhatsApp users remain safe?
The best way to avoid unwanted attachments is to avoid them (e.g., files that were downloaded without an explanation).
If a colleague or contact suddenly sends an account statement, invoice, payment document, or other file that you were not expecting, verify it before opening. Contact the sender through a different method (e.g., phone call) and check if they actually sent it.
Users should be particularly careful of executable files and script files. A file that seems to be a routine document but has an unusual file extension should not be opened.
CERT-In has advised users to keep security software updated and to not run files that are not valid and/or come from unknown sources. It also advised users to regularly check WhatsApp's Linked Devices section and to log out of sessions which are no longer needed.
The Indian government has also warned about another WhatsApp-based campaign involving fake “Statement of Account,” “RBI” and “MCA” files. In that campaign, malicious Windows executables were hidden inside compressed ZIP files and used to compromise devices and may hijack active WhatsApp Web sessions.
WhatsApp users should treat unexpected files with the same caution as suspicious email attachments. A message from a known contact is not proof that the attachment is safe.
It is safest, then, to stop and verify the sender through another channel, update your operating system and security software, and not run any unfamiliar files on your computer. A few seconds of verification can stop a much bigger security problem as attackers increasingly abuse trust between contacts.