• About us
  • Contact us
Tuesday, June 30, 2026
No 1 epaper in Sri Lanka
  • News
  • Politics
  • Sports
  • Foreign
  • Entertainment
  • Business
  • Political Analysis
  • Inside Politics
  • EPAPERPDF
  • සිංහලSINHALA
No Result
View All Result
  • News
  • Politics
  • Sports
  • Foreign
  • Entertainment
  • Business
  • Political Analysis
  • Inside Politics
  • EPAPERPDF
  • සිංහලSINHALA
No Result
View All Result
Mawratanews.lk | Sri Lanka Latest Sinhala News and Headlines
No Result
View All Result
Home Business

Kaspersky uncovers a new massive campaign spreading malware via WhatsApp

June 30, 2026
in Business
Reading Time: 12 mins read
A A
Kaspersky uncovers a new massive campaign spreading malware via WhatsApp
Share on FacebookShare on Twitter

Targeting WhatsApp Desktop and WhatsApp Web users, the crimeware campaign distributes malicious VBScript files via direct messages on the platform. Victims have been identified across multiple countries and territories, including Malaysia, Brazil, Singapore, Taiwan and Vietnam, with the highest number of observed victims located in Malaysia. The use of multiple languages in file names also points to broad regional targeting, especially across Europe.

The campaign was revealed in June 2026 by Kaspersky Global Research and Analysis Team (GReAT). According to their research, the crimeware actor uses WhatsApp accounts that have been previously compromised to distribute malicious attachments. The messages are sent from those accounts’ existing contacts, which increases the likelihood that recipients will view the files. Once installed, the malware enables remote access to the system through standard administrative capabilities intended for legitimate IT support and management use.

The social engineering component relies on file names designed to resemble routine business documents. Observed examples include invoices, bank statements, account statements, payment records, and debt notices. File names are also localized into multiple languages, including English, Portuguese, French, German, and Malay, indicating distribution across different language regions. In addition, the VBScript samples contain extensive comments and metadata intended to mimic legitimate Microsoft Windows Update components. 

“In this campaign, attackers are exploiting trust within messaging platforms by using compromised WhatsApp accounts to deliver malicious attachments that appear to originate from known contacts, making recipients far more inclined to engage with them. The file names are carefully disguised as routine business documents, such as invoices and payment notices, and localized across multiple languages to support broad targeting. Once opened, they trigger a staged infection chain that silently retrieves and executes additional malicious components from external infrastructure,” says Fareed Radzi, security researcher at Kaspersky GReAT.

The execution flow of the attachment follows a multi-stage process on the affected system. Once opened, the file triggers a scripted sequence on the device. The initial script creates a working directory under C:\Users\Public\Documents\, then retrieves additional script files from external infrastructure and executes them using Windows Script Host. These follow-up scripts perform additional system actions and download a compressed archive from the same infrastructure. The archive contains an installation package for remote monitoring and management software. 

The full report is available on Securelist.com. Kaspersky GReAT experts recommend users to: Be cautious when receiving unexpected attachments through WhatsApp, even when they appear to originate from known contacts, as they may be able to execute malware. Do not open script and executable file types such as .vbs, .vbe, .exe, .bat, .cmd, .js, and .ps1 unless their legitimacy has been independently verified. Use a strong security solution on all computers and mobile devices, such as Kaspersky Premium. It will warn you and prevent any infection.

Photo Caption: Examples of WhatsApp messages containing the malicious VBScript file

    Share51Tweet32Send
    Previous Post

    People’s Insurance PLC Strengthens Industry Leadership Through International Recognition and Outstanding Sales Excellence

    Next Post

    Sampath Bank Launches Sri Lanka’s First Real-Time USD Payment Solution for Sri Lanka Ports Authority Users

    MORE NEWS

    Sampath Bank Launches Sri Lanka’s First Real-Time USD Payment Solution for Sri Lanka Ports Authority Users
    Business

    Sampath Bank Launches Sri Lanka’s First Real-Time USD Payment Solution for Sri Lanka Ports Authority Users

    June 30, 2026
    People’s Insurance PLC Strengthens Industry Leadership Through International Recognition and Outstanding Sales Excellence
    Business

    People’s Insurance PLC Strengthens Industry Leadership Through International Recognition and Outstanding Sales Excellence

    June 30, 2026
    Corporate Roundtable on Disability-Inclusive Recruitment                                         
    Business

    Corporate Roundtable on Disability-Inclusive Recruitment                                         

    June 29, 2026
    Vietjet opens bookings for first-ever direct flights between Sri Lanka and Vietnam
    Business

    Vietjet opens bookings for first-ever direct flights between Sri Lanka and Vietnam

    June 26, 2026
    Tokyo Cement inspires Future-Ready Construction at BUILD BEYOND 2026 Technology Summit
    Business

    Tokyo Cement inspires Future-Ready Construction at BUILD BEYOND 2026 Technology Summit

    June 26, 2026
    Union Assurance Celebrates a Legacy of Excellence at Agency Distribution Annual Awards 2025
    Business

    Union Assurance Celebrates a Legacy of Excellence at Agency Distribution Annual Awards 2025

    June 26, 2026
    Load More

    One of the best Sri Lanka Latest News Website and Sinhala language newspaper with Sunday editions, published by Free Media Independent Networks Pvt Ltd.

    • About us
    • Contact us

    Copyright © 2019–2025 Free Media Independent Networks Pvt Ltd. All Rights Reserved. Developed by Turn Global.

    No Result
    View All Result
    • News
    • Politics
    • Sports
    • Foreign
    • Entertainment
    • Business
    • Political Analysis
    • Inside Politics
    • EPAPER
    • සිංහල

    Copyright © 2019–2025 Free Media Independent Networks Pvt Ltd. All Rights Reserved. Developed by Turn Global.