The broken assumption is that a file from a known WhatsApp contact is safe to open. In this campaign, a compromised account turns the recipient list itself into the delivery channel, so normal suspicion and email-style filtering miss the path in.
Kaspersky says the campaign is active globally and mainly hits WhatsApp Desktop and WhatsApp Web users. The messages carry VBS attachments disguised as invoices or other business documents, and execution leads to a legitimate UEMS RMM agent that gives the attacker remote access.
That makes the end state look like ordinary remote-support software, not obvious malware. Any team that lets staff trade files through WhatsApp or similar chat apps has the same trust problem: one hijacked account can spray the contact list and widen the blast radius fast.