A known chat contact has become the delivery path, and the payload is not a flashy stealer but a legitimate admin tool that can blend into normal support traffic. That makes this campaign harder to spot than a typical attachment scam because the end result looks like routine IT management, not obvious malware activity.
Kaspersky says the active campaign is using WhatsApp Desktop and WhatsApp Web to push obfuscated VBScript files that pose as business and financial documents across Malaysia, Brazil, India, Mexico, Singapore, the U.K., Spain, Taiwan, Australia, Russia, and Vietnam, with Malaysia seeing the most victims. The script then installs ManageEngine Endpoint Central for remote access, and the attackers appear to be using compromised WhatsApp accounts to reach their contacts.