- Cybercriminals use compromised accounts to send malicious files to their trusted contacts.
- The threat comes disguised in files with the .vbs extension that pretend to be invoices or financial reports.
- The ultimate goal is to install a remote management tool to take full control of the victim's PC.
- This campaign particularly affects users in Spain who use WhatsApp Web or the Windows version.
A serious attack has been detected circulating on WhatsApp chats, putting cybersecurity experts on high alert. It turns out that a group of attackers is using real accounts to send malicious content. malicious files that infect Windows computerstaking advantage of the trust we usually have with our lifelong contacts.
Although Spain is one of the hotspots where this issue has been observed, its reach is international and affects both web and desktop application users. What seems like a simple work document can end up opening the doors wide to strangers who want to control your equipment as they please, a problem that has already spread to countries such as the United Kingdom, Mexico, Brazil, and India.
How does the deception work through VBS files?

Cybercriminals don't bother with common files like PDFs or Word documents; instead, they use VBS scripts that the operating system executes almost without question. These files often have names that They simulate invoices, bank statements, or financial reports of utmost importance to pique your curiosity and make you click without thinking twice, falling into the trap in a jiffy.
The worst part is that the code in these scripts is heavily obfuscated, which in plain English means that it's hidden so that antivirus software doesn't detect it At the first opportunity. Upon opening it, the script doesn't show anything suspicious at first, but behind the scenes it starts downloading more junk from the attackers' servers to prepare the ground.
For the attack to work, the user must be using WhatsApp on a PC, since this type of file They are designed to attack Windows systems. exclusively. On an Android or iPhone mobile device, the file usually does nothing, but if you use the application installed on the computer, the wscript.exe process can automatically launch the infection as soon as the document is downloaded.
The danger of hijacked WhatsApp accounts

One of the points that most worries the researchers is that the messages do not come from unknown numbers, but from friends or coworkers whose accounts have been previously hacked. This makes us completely let our guard down, since you don't expect an acquaintance to send you a virus through chat just like that.
What a mess, because it's still not known for sure how they manage to access the initial victims' accounts, although it's suspected that techniques such as cookie theft or hijacking open sessions. What is clear is that, once inside, they use the contact list to continue spreading the malicious file like a snowball.
The strategy is very clever because the document names are adapted to the language of each country, which It makes the deception much more believable. For the average user, if you receive a file called 'Payment Report' or 'Invoice Notice' from someone you trust, you'll most likely end up clicking on it, and that's where the real trouble for your privacy begins.
From a simple file to total PC control

When the script runs, the first thing it does is modify the Windows Registry to disable system security alertsThose pop-up windows that ask if you want to allow changes to your computer. With defenses down, the malware downloads a legitimate program called ManageEngine Endpoint Central, which is typically used by IT professionals to repair computers remotely.
The problem is that, in this case, the software is installed silently and connects directly to the criminals' servers. This allows them have full access to your files, see what you do on screen and even install other more dangerous programs without you noticing anything while you work peacefully.
To avoid being taken advantage of with these kinds of schemes, the wisest thing to do is Never open files with the .vbs extensionEven if it comes from a known contact, if you have any doubts, it's best to call the person who sent it to confirm its legitimacy before compromising your entire system's security.
To put an end to this mess, it's vital that we tread carefully and always keep our antivirus software updated, as well as being suspicious of any financial document that arrives unsolicited. The key is not to trust anyone, not even our own shadow, when it comes to... strange files in WhatsApp, in as much as A simple click can cause us distress. monumental and leaving our personal information in the hands of the wrong people.
