India’s national cybersecurity watchdog CERT-In issues an advisory warning that a large-scale malware distribution campaign targets WhatsApp Web and WhatsApp Desktop users. The advisory says the campaign spreads through direct messages that include malicious Visual Basic Script (VBScript) attachments. CERT-In notes that attackers use WhatsApp accounts that have already been compromised to send these attachments to victims. Because the messages come from contacts the recipient is likely to trust, the attachment may appear legitimate and recipients may be more likely to open it.

According to information cited in the advisory from Kaspersky and Securelist, if a user clicks on or executes the VBScript file, the malware can grant attackers unauthorised remote access to the infected device. CERT-In warns this can enable theft of login credentials, use of those credentials for fraud, installation of additional malware, and potential infection of other systems connected to the user’s device. The advisory also emphasises that users should treat unexpected attachments cautiously, even if they appear to come from a friend, colleague, or family member, and suggests verifying with the sender through another communication channel before opening files.