New WhatsApp Web and Desktop Threat: CERT-In Issues Urgent Warning
Users of WhatsApp Web and WhatsApp Desktop are facing a fresh wave of cyberattacks, prompting India’s Computer Emergency Response Team (CERT-In) to release a critical security alert. Scammers have adopted a more deceptive method to compromise systems, and the danger is amplified because malicious files can appear to come from trusted contacts.
How the Scam Operates
According to CERT-In, cybercriminals first compromise a legitimate WhatsApp account. Once they gain control, they use that account to send fraudulent business documents to the victim’s saved contacts. Because the message originates from a familiar name or number, the recipient is far less likely to suspect anything unusual. The moment the file is opened, the attack chain is triggered.
Who Is Most at Risk?
This threat primarily targets individuals who use WhatsApp Web or the WhatsApp Desktop application on a Windows computer. The attackers are specifically focusing on Windows users, making it essential for anyone in this group to exercise heightened caution. Even if a file arrives from a known contact, cross-verification is strongly advised before opening it.
Types of Files Used in the Attack
CERT-In reports that scammers are relying on Visual Basic Script (.vbs) files to deliver the malware. To make these files appear authentic, they are disguised with names that suggest official or financial content, such as:
- Invoices
- Payment records
- Bank statements
- Account summaries
- Microsoft Windows update notifications
This careful naming strategy is designed to eliminate any suspicion the user might have.
What Happens When the File Is Opened?
If a user mistakenly opens a .vbs file, a script immediately activates on the Windows system. This can lead to several dangerous outcomes, including:
- Automatic download of additional malware
- Remote access to the computer by hackers
- Theft of passwords and personal data
- Installation of other harmful software
- Potential compromise of the entire network
Key Safety Recommendations from CERT-In
The cybersecurity agency has outlined several practical steps to help users protect themselves from this evolving threat. Anyone using WhatsApp on a laptop or desktop should follow these guidelines:
- Avoid opening any suspicious files received via WhatsApp, regardless of who appears to have sent them.
- Stay away from files with a .vbs extension, as these are the primary vector for this attack.
- If a file is sent by a known contact, verify its authenticity through a phone call or alternative communication channel before opening.
- Keep the Windows operating system and antivirus software updated to the latest versions.
- Refrain from clicking on questionable links or opening attachments from unknown sources.
