Cybercriminals are using compromised WhatsApp accounts to distribute malicious files disguised as invoices and bank documents

Kaspersky Warns of WhatsApp Malware Campaign Using Fake Business Documents

Kaspersky has uncovered a large-scale malware campaign targeting WhatsApp users. Attackers are exploiting compromised accounts to send fake invoices and banking documents that install malware and enable remote access to victims' computers.

Kaspersky Warns of WhatsApp Malware Campaign Using Fake Business Documents
Jun 29, 2026 10:51

Global cybersecurity company Kaspersky has uncovered a new malware campaign that uses WhatsApp to distribute malicious files disguised as legitimate business documents.

June 29, Monday, the company disclosed the findings in a press release.

According to Kaspersky's Global Research and Analysis Team (GReAT), cybercriminals are exploiting compromised WhatsApp accounts to send malicious files to trusted contacts.

The files are disguised as invoices, bank statements and payment-related documents. They are also given filenames in multiple languages and structured to resemble legitimate Windows update files, increasing the likelihood that recipients will open them.

Kaspersky security researcher Farid Radji said the attackers are exploiting users' trust in familiar contacts. Once the file is opened, a multi-stage infection process begins. The malware then downloads additional malicious components from the internet.

According to the company, the attack first creates a new folder on the victim's device before downloading additional scripts. It then installs remote monitoring and management software, allowing attackers to gain remote access and control of the compromised computer.

Kaspersky advises users not to open unexpected files received through WhatsApp, even if they appear to come from someone they know.

The company also recommends verifying the authenticity of executable or script-based files before opening them and using trusted, regularly updated security software on both computers and mobile devices.

//DBTech/RI/MI//