Back to all lessons
Awareness Lessons
4 months ago

Fake Business Docs on WhatsApp Deploy Remote Access Malware

Attackers are exploiting user trust in familiar messaging platforms by disguising malicious VBScript files as routine business documents on WhatsApp. Once executed, these scripts silently install legitimate remote management software (ManageEngine Endpoint Central), effectively handing attackers full system access while evading suspicion by abusing a trusted tool. This attack succeeds primarily because users lack awareness of file-type risks in messaging apps and organizations fail to restrict execution of script files on endpoints. The use of legitimate software as a payload makes detection significantly harder, highlighting the danger of 'living-off-the-land' and trusted-tool abuse techniques.

Tactical Insight

Immediate actions

  • Block execution of script file types (e.g., .vbs, .js, .ps1) on endpoints via application control or Group Policy.
  • Audit all installed remote management tools across the environment and remove any unauthorized installations immediately.

Long-term improvements

  • Implement application whitelisting to prevent unauthorized software, including dual-use remote admin tools, from being installed or executed.
  • Establish a policy requiring all business file exchanges to occur through sanctioned, monitored platforms rather than consumer messaging apps.
  • Deploy endpoint detection and response (EDR) solutions configured to alert on unusual remote management tool installations.

Detection measures

  • Monitor and alert on anomalous outbound connections originating from remote management software to unknown or unregistered management servers.
  • Enable centralized logging of script execution events (e.g., via Windows Event ID 4688 or PowerShell Script Block Logging) and review alerts regularly.
  • Conduct phishing simulation exercises that include messaging-app-based attack scenarios to improve employee detection skills.