

A new WhatsApp-based malware campaign is targeting business users by sending malicious files disguised as ordinary financial and administrative documents, cybersecurity researchers have warned. The campaign is particularly concerning because attackers are using compromised WhatsApp accounts to contact people already known to the account holder, making the messages appear more trustworthy.
Quick Heal Technologies warned that the campaign is affecting finance teams, senior executives, chartered accountants and other business users. The company said its researchers at Seqrite Labs have observed the operation evolving rapidly as attackers change file formats and methods to bypass security controls.
Unlike conventional phishing attempts that come from unfamiliar numbers, this campaign exploits existing WhatsApp relationships. Once an account has been compromised, attackers can use it to send suspicious attachments to contacts already saved by the victim.
This makes the scam harder to spot. A message from a colleague, business associate, or known contact may appear legitimate at first glance, especially when the attached file seems related to an ongoing financial or administrative task.
Researchers have found malicious attachments presented as routine business paperwork, including invoices, account statements, payment records and debt-related notices. Attackers have also used different languages and variations of document names, suggesting that the campaign is designed to reach users across multiple markets.
The campaign primarily affects people using WhatsApp Desktop and WhatsApp Web on Windows systems. Security researchers say the malicious scripts can trigger a multi-stage infection process after being opened, eventually giving attackers remote access through legitimate remote-management software.
Using legitimate software as part of the attack makes detection more complicated. Instead of relying solely on obviously malicious programs, attackers can abuse tools normally used for remote IT administration.
The combination of compromised accounts, familiar contacts, and apparently routine documents gives the campaign several layers of social engineering. According to security researchers, this trust-based approach can significantly increase the chances that a recipient will open an attachment.
Also Read: WhatsApp Raises Android Requirement: These Older Phones Lose Support
Cybersecurity experts advise users not to open unexpected files just because they come from someone they know. If a contact sends an unusual invoice, statement or payment-related document, users should confirm the request through another communication channel before opening it. Keeping security software updated, avoiding suspicious attachments and enabling appropriate account protections can also reduce the risk.