Threats Tagged 'whatsapp'
View all threats tagged with 'whatsapp'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'whatsapp'
Click on any threat for detailed analysis and mitigation recommendations
A sophisticated scam is spreading through WhatsApp that exploits the platform's legitimate 'Linked devices' feature to take over user accounts. Attackers compromise existing accounts and send messages to contacts asking them to vote for a friend or relative in various online contests. When victims click the provided link, they are redirected through pages appearing to be WhatsApp-related, often using the legitimate wa.me domain. The attack tricks users into authorizing a new linked session, granting attackers full access to read messages, send messages as the victim, and access contacts. The scam is particularly effective because it comes from known contacts and relies on trust and quick reactions. Once compromised, attackers can continue the scam by messaging the victim's contacts, creating a chain of account takeovers without triggering traditional security alerts. Join the discussion | AlienVault OTX General | 08/04/2026, 07:17:39 UTC Added: 08/04/2026, 08:18:17 UTC |
An active malware campaign has been discovered distributing malicious VBScript files through WhatsApp direct messages since June 2026. The operation affects users across multiple countries, with Malaysia experiencing the highest concentration of victims. Attackers compromise WhatsApp accounts and send weaponized VBS files disguised as business and financial documents to contacts. The multi-stage infection chain ultimately deploys legitimate ManageEngine Endpoint Central RMM software, providing persistent remote access to compromised systems. The scripts employ heavy obfuscation, Chinese-language comments, and modify Windows UAC settings. Infrastructure overlaps with ValleyRAT and Gh0st RAT operations suggest possible Chinese-speaking operators, though attribution remains uncertain. The campaign primarily targets individual users through opportunistic rather than focused methods, exploiting social engineering techniques with localized filenames in multiple languages. Join the discussion | AlienVault OTX General | 06/22/2026, 11:01:01 UTC Added: 06/22/2026, 20:24:23 UTC |
European governments are transitioning from encrypted messaging applications like Signal and WhatsApp to sovereign Matrix-based solutions. This shift follows successful phishing campaigns, primarily attributed to Russian intelligence services, exploiting Signal's linked devices feature to gain persistent access to political communications. While Signal was initially recommended for external communications, scope creep led to its widespread use for sensitive statecraft discussions. Matrix-based systems offer advantages including federated architecture, government-controlled identity platforms, and customizable data retention policies. However, these homegrown solutions introduce new security vulnerabilities and implementation challenges. The walled-garden nature of current sovereign systems limits their utility for international diplomacy, suggesting Signal will continue to be used for communications with external parties despite the security concerns. Join the discussion | AlienVault OTX General | 05/21/2026, 08:39:24 UTC Added: 05/21/2026, 16:44:45 UTC |
A sophisticated malware campaign targeting WhatsApp users has been observed since February 2026. The attack chain begins with malicious Visual Basic Script files sent via WhatsApp messages, which, when executed, initiate a multi-stage infection process. The malware uses renamed Windows utilities, retrieves payloads from trusted cloud services, and installs malicious MSI packages. The campaign employs social engineering, stealth techniques, and cloud-based payload hosting to establish persistence and escalate privileges on victim systems. The attackers utilize legitimate tools and trusted platforms to reduce visibility and increase the likelihood of successful execution. The final stage involves the delivery of unsigned MSI installers that enable remote access to compromised systems. Join the discussion | AlienVault OTX General | 03/31/2026, 16:35:36 UTC Added: 03/31/2026, 18:38:16 UTC |
The Boto Cor-de-Rosa campaign reveals Astaroth's new strategy of exploiting WhatsApp Web for propagation. This Brazilian banking malware now uses a Python-based worm module to retrieve victims' WhatsApp contact lists and automatically send malicious messages, expanding its infection reach. The attack begins with a malicious ZIP file sent via WhatsApp, containing a Visual Basic script that downloads additional components. The malware then operates two parallel modules: a propagation module for spreading through WhatsApp contacts, and a banking module for credential stealing. This campaign demonstrates Astaroth's evolution, combining traditional malware techniques with sophisticated social engineering and multi-platform propagation, primarily targeting Brazilian users. Join the discussion | AlienVault OTX General | 01/08/2026, 18:12:03 UTC Added: 01/09/2026, 09:26:35 UTC |
A sophisticated Android malware campaign distributes a malicious 'RTO Challan / e-Challan' APK via WhatsApp, targeting users with a fraudulent payment app. The malware employs advanced obfuscation and hidden installation techniques to maintain persistence and control over infected devices. It establishes a custom VPN tunnel to conceal network traffic and harvests extensive personal, device, and financial data. Key capabilities include OTP interception, call behavior manipulation, and presenting fake payment interfaces to steal banking credentials. The command-and-control infrastructure uses obfuscated Base64-encoded URLs linked to malicious domains. This campaign combines social engineering, mobile malware, and financial fraud, posing a significant risk of monetary loss and identity theft. Although no CVSS score is assigned, the threat severity is assessed as high due to the impact and exploitation ease. European organizations with Android users, especially those using WhatsApp and mobile banking, should be vigilant. Mitigation requires targeted user awareness, mobile security hygiene, and network monitoring for suspicious VPN tunnels and domain connections. Join the discussion | AlienVault OTX General | 12/12/2025, 10:09:15 UTC Added: 12/12/2025, 12:53:34 UTC |
The Water Saci campaign is a sophisticated malware operation primarily targeting Brazilian banking and cryptocurrency platforms via WhatsApp. It employs multi-format malware delivery using various scripting languages, including a shift from PowerShell to Python, likely enhanced by AI tools to evade detection and complicate analysis. The malware features aggressive anti-sandbox techniques, extensive backdoor capabilities, and persistence mechanisms. Although currently focused on Brazil, the use of WhatsApp as a propagation vector and targeting financial applications poses a potential risk to European organizations with ties to Brazilian markets or users. The campaign’s complexity and AI-enhanced development pipeline indicate a medium severity threat with significant evasion and persistence capabilities. Defenders should prioritize monitoring WhatsApp-based phishing attempts, scrutinize multi-format file attachments, and implement advanced behavioral detection to mitigate risks. Countries with strong economic or diaspora links to Brazil and high WhatsApp usage are more likely to be affected. Join the discussion | AlienVault OTX General | 12/02/2025, 14:44:59 UTC Added: 12/03/2025, 17:44:04 UTC |
A phishing campaign targeting Brazilian users spreads a banking trojan via WhatsApp Web by leveraging an open-source automation script. The attack starts with a malicious VBS script in a phishing email that downloads and executes an MSI installer and another VBS script. The second VBS installs Python and Selenium to inject malicious JavaScript into WhatsApp Web, enabling the malware to propagate by sending itself to the victim's contacts. The MSI drops an AutoIt script that monitors for Brazilian banking and cryptocurrency application windows and loads an encrypted payload into memory to evade detection. This payload specifically targets Brazilian financial institutions and cryptocurrency wallets. The campaign uses in-memory execution and automation to maintain stealth and persistence. No known exploits in the wild have been reported yet, and the campaign is currently assessed as medium severity. The attack is highly tailored to Brazilian users and financial targets but could pose risks if similar tactics spread elsewhere. Join the discussion | AlienVault OTX General | 11/24/2025, 12:02:31 UTC Added: 11/24/2025, 12:21:39 UTC |
A malware campaign targeting WhatsApp users primarily in Brazil uses WhatsApp's 'View Once' message feature to deliver malicious ZIP archives containing VBS or HTA files. These files execute PowerShell scripts to download additional payloads, including scripts that steal WhatsApp user data and an MSI installer deploying the Astaroth banking trojan. The campaign evolved from IMAP-based to HTTP-based command and control communication and leverages Selenium Chrome WebDriver and the WPPConnect JavaScript library to hijack WhatsApp Web sessions, steal session tokens and contacts, and distribute spam. Over 250 victims have been identified, with 95% located in Brazil and some impact noted in Austria. The attack enables credential theft, session hijacking, persistence, and financial fraud through banking trojan deployment. No CVE or known exploits in the wild are reported, and the campaign is rated medium severity. Defenders should focus on user awareness, endpoint detection of PowerShell and script execution, and monitoring for suspicious WhatsApp Web activity. Join the discussion | AlienVault OTX General | 11/20/2025, 19:42:41 UTC Added: 11/20/2025, 22:13:41 UTC |
This intelligence report examines the connection between two Brazilian banking trojans, Maverick and Coyote. The malware spreads through WhatsApp, using a multi-stage attack that begins with a malicious LNK file. Both trojans share similarities in their infection methods, targeting Brazilian users and banks. The attack chain involves obfuscated PowerShell commands, downloading additional payloads from command and control servers. The malware employs anti-analysis techniques and targets specific browsers. Persistence is achieved through a batch file in the startup folder. The report provides technical details, including code samples and infection chain analysis, as well as indicators of compromise for the identified malware campaign. Join the discussion | AlienVault OTX General | 11/12/2025, 09:45:13 UTC Added: 11/12/2025, 09:48:28 UTC |
Showing 1 to 10 of 12 results