WhatsApp Malware Alert: Dangerous Attachments Could Put Your Computer and Data at Risk
- bysagar
- 29 Aug, 2026
WhatsApp users are being warned to be more careful when opening files received through chats, particularly while using the messaging platform on a computer. Cybercriminals are reportedly circulating malicious attachments that are designed to look like ordinary business documents. Opening one of these files could allow malware to enter the system and potentially expose sensitive information.
Cybersecurity researchers at Kaspersky have identified a malware campaign in which attackers are reportedly using compromised WhatsApp accounts to distribute harmful files. The tactic is particularly concerning because a malicious attachment may appear to have been sent by someone the recipient already knows.
Instead of relying only on messages from unfamiliar numbers, the attackers can take advantage of previously compromised accounts. This can make the communication appear more trustworthy and increase the likelihood that a recipient will open the attached file.
WhatsApp Web and Desktop Users Being Targeted
According to findings from Kaspersky's Global Research and Analysis Team (GReAT), the campaign has been observed targeting people who access WhatsApp through its desktop and web versions.
The attackers reportedly send malicious attachments directly through WhatsApp conversations. These files can be disguised with names that resemble legitimate business documents, invoices or other work-related material.
This approach is designed to reduce suspicion. A person who regularly receives documents through WhatsApp for professional or personal purposes may assume the attachment is genuine, particularly if the message appears to come from a familiar contact.
However, opening an unexpected attachment without verifying it could expose the computer to malicious software.
Malicious VBScript Files Used in the Campaign
Researchers found that the campaign involves dangerous VBScript files. VBScript is a scripting technology associated with Windows environments, and malicious scripts can be created to perform unwanted actions when executed.
The files identified in the campaign were reportedly given convincing document-style names rather than obvious labels that would immediately raise suspicion.
This is an important detail because cybercriminals increasingly rely on social engineering instead of simply sending suspicious-looking files. The goal is to make users believe they are opening a routine document.
Once a malicious script is executed, it may trigger malware on the computer. Depending on the type of malware involved, a compromised device could potentially face risks such as data theft, unauthorized access or other harmful activity.
Compromised WhatsApp Accounts Make the Attack More Convincing
One of the biggest warning signs highlighted by the campaign is that users should not automatically trust an attachment simply because it comes from a saved contact.
Researchers say attackers are using WhatsApp accounts that have already been compromised to distribute malicious files. As a result, recipients may see the name or profile of someone they recognize and assume the message is safe.
For example, an unexpected invoice, payment document, business proposal or other attachment from a known contact could still be dangerous if that person's WhatsApp account has been compromised.
Users should therefore verify unusual attachments with the sender before opening them, particularly when the message is unexpected or lacks a clear explanation.
Users in Several Countries Reportedly Targeted
The malicious files have reportedly appeared with names in several languages, including English, Portuguese, French and German. According to Kaspersky's findings, the campaign has affected users across multiple countries, with Malaysia, Brazil and Singapore among the locations highlighted.
The presence of files in different languages suggests that such campaigns are not necessarily limited to one geographical region.
Although the reported campaign has focused on users in several countries, Indian WhatsApp users should also follow basic cybersecurity precautions because similar malware distribution techniques can be adapted to target users in other markets.
How to Stay Safe From Suspicious WhatsApp Attachments
The simplest precaution is to avoid opening unexpected files, especially those received from unknown numbers. However, messages from known contacts should not be treated as automatically safe either.
If someone unexpectedly sends a business document, script, archive or unusual attachment, contact that person separately and confirm whether they actually sent it.
Users should also pay attention to unusual file extensions rather than relying only on the displayed filename. Keeping the operating system, browser, WhatsApp application and security software updated can further reduce exposure to known vulnerabilities.
Be especially cautious when using WhatsApp Web or the desktop application for work-related communication, where document sharing is common and a malicious file may more easily blend in with legitimate attachments.
The broader lesson from this malware campaign is straightforward: familiarity does not always equal safety. Cybercriminals can exploit compromised accounts and convincing filenames to make dangerous files appear legitimate. Verifying an unexpected attachment before opening it can prevent a seemingly harmless WhatsApp message from turning into a serious cybersecurity problem.





