A WhatsApp Message Could Be All It Takes to Give Criminals Access to Your PC
Many people assume cybercriminals rely on suspicious emails to trick their victims. Increasingly, however, attackers are moving their efforts to platforms that users trust more, including WhatsApp.
Security researchers have recently identified a campaign targeting WhatsApp users across multiple countries, including the UK, where attackers are using compromised accounts to distribute malware disguised as legitimate business documents.
Why This Attack Is Different
The messages don't arrive from unknown numbers or obvious scammers.
Instead, they appear to come from genuine contacts whose WhatsApp accounts have already been compromised. This immediately lowers suspicion and increases the likelihood that recipients will trust the file they receive.
The files are typically named to resemble common business documents such as:
- Financial reports
- Invoices
- Account statements
- Payment notifications
- Billing documents
For a busy employee receiving dozens of documents every day, opening such a file may seem completely routine.
What Happens When the File Is Opened?
The malicious attachment is not actually a document at all.
It is a Windows script file designed to launch a series of actions behind the scenes once opened. The script contacts attacker-controlled servers, downloads additional components and modifies Windows settings to reduce security protections.
The end result is the installation of remote management software that allows the attacker to gain control of the device.
Interestingly, the software being abused is a legitimate IT management tool commonly used by IT departments to administer computers remotely. The criminals simply configure it to connect back to infrastructure under their control rather than a genuine IT support provider.
From that point, attackers may be able to:
- Access files stored on the device
- Install additional malware
- Capture credentials
- Move deeper into the organisation's network
- Maintain ongoing access without the user's knowledge
A Global Campaign
Researchers have observed victims across numerous countries, including:
- United Kingdom
- Australia
- Spain
- Singapore
- India
- Brazil
- Mexico
- Taiwan
- Vietnam
- Malaysia
- Russia
The use of localised file names in different languages suggests the campaign has been specifically adapted for international targets rather than being aimed at a single region.
Why Trusted Contacts Cannot Always Be Trusted
One of the most important lessons from this campaign is that trust alone is no longer a reliable security control.
If a colleague, supplier, customer or friend has had their WhatsApp account compromised, any files they send could potentially be malicious.
This doesn't mean you should become suspicious of everyone. It does mean that unusual file types, unexpected documents or unsolicited attachments should always be verified before being opened.
A quick phone call or separate message could prevent a significant security incident.
Practical Steps to Reduce Risk
Businesses should remind staff to:
- Treat unexpected file attachments with caution, even when they come from known contacts.
- Verify unusual requests through a second communication channel.
- Never open script files or executable files unless their source is absolutely certain.
- Ensure endpoint protection software is installed and regularly updated.
- Report suspicious messages immediately to IT support.
- Keep operating systems and applications fully patched.
The Bigger Picture
This attack highlights a growing trend in cybercrime. Criminals are increasingly targeting collaboration and messaging platforms because users naturally trust them more than traditional email.
The challenge for organisations is no longer simply filtering malicious emails. It is creating a culture where employees understand that threats can arrive through any communication channel.
Whether it comes through email, WhatsApp, Teams, Slack or SMS, the question remains the same:
How do you know the file is genuine?
Because when it comes to cyber security, trust is useful — but evidence is better.



