Quick Heal Technologies Limited has issued a warning on an ongoing WhatsApp-based malware campaign targeting finance teams, senior executives, chartered accountants and individual business users. According to the cybersecurity firm, the campaign spreads through compromised WhatsApp accounts and is evolving rapidly, with attackers adopting new file formats and evasion methods to bypass security controls and establish persistent access to victims’ devices.
Study found hackers using WhatsApp to distribute malicious files
The company cites an investigation conducted by its researchers at Seqrite Labs. The study shows that the campaign relies on trust rather than unsolicited messages from unknown numbers. Once a WhatsApp account is compromised, attackers use it to forward malicious files to the account holder’s existing contacts. Because the messages appear to come from a known colleague, client, friend or business associate, recipients may be more likely to open the attachment without independently verifying it.As per the study, the attackers are using finance- and compliance-themed filenames to create urgency and familiarity. Malicious attachments have been disguised as routine business documents, including “Financial Report,” “Account Statement,” “Outstanding Payment List” and “Debt Confirmation.” Some variants also impersonate urgent communications from regulatory institutions, including the Reserve Bank of India and the Ministry of Corporate Affairs, in an effort to pressure recipients into opening the files immediately.
How the campaign works
The campaign evolves through several delivery methods. It initially spreads through malicious Visual Basic Script files, or .vbs files, sent directly through WhatsApp. The attackers later shifted to ZIP archives carrying an executable and a supporting malicious file, using DLL sideloading to make a legitimate-looking program load harmful code. The company cautions that .img and .vhd files are not ordinary photographs or documents.When a user double-clicks one of these files, Windows treats it like a newly connected disk drive, potentially exposing an executable and concealed malicious components. Users should treat an unexpected .img or .vhd attachment with the same caution they would apply to an unknown .exe file.Infected systems can use an active WhatsApp Web session to automatically forward the malicious file to the victim’s contacts, allowing the campaign to propagate further through trusted social and professional networks. The self-propagating feature expands the risk from an individual compromise into a wider business and supply-chain concern, particularly where employees, vendors, customers and finance functions communicate frequently over WhatsApp.
What WhatsApp users must do to avoid falling victims
Quick Heal Technologies Limited recommends that organisations and individuals never open an unexpected file received on WhatsApp or any messaging platform, even if it appears to come from a known contact. Recipients should verify the attachment through a separate channel, such as a phone call, rather than replying in the same conversation. Users should also routinely review WhatsApp’s Linked Devices settings and log out of web or desktop sessions they do not recognise or no longer use.The company also advises organisations to maintain updated endpoint protection, prohibit unauthorised remote-access software, monitor for suspicious driver installations and alert employees to the risks posed by finance-themed attachments and pressure-based messages. If a compromise is suspected, users should immediately log out of WhatsApp-linked devices, disconnect the affected device from the network, inform their IT or security team, and warn their contacts not to open files sent from their number.
