[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fKbQ1Gd_LAWZq3CM5EHFxGQrJo7_enZfAMyOVC1FSzKw":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":49},"b7ba50e0-0a6e-49c3-8da7-054ed34e5e97","fake-business-docs-on-whatsapp-deploy-remote-access-malware","0094951c-6596-47c1-9227-426cfa2ffceb","Fake Business Docs on WhatsApp Deploy Remote Access Malware","Attackers are exploiting user trust in familiar messaging platforms by disguising malicious VBScript files as routine business documents on WhatsApp. Once executed, these scripts silently install legitimate remote management software (ManageEngine Endpoint Central), effectively handing attackers full system access while evading suspicion by abusing a trusted tool. This attack succeeds primarily because users lack awareness of file-type risks in messaging apps and organizations fail to restrict execution of script files on endpoints. The use of legitimate software as a payload makes detection significantly harder, highlighting the danger of 'living-off-the-land' and trusted-tool abuse techniques.","**Immediate actions:**\n- Block execution of script file types (e.g., .vbs, .js, .ps1) on endpoints via application control or Group Policy.\n- Audit all installed remote management tools across the environment and remove any unauthorized installations immediately.\n\n**Long-term improvements:**\n- Implement application whitelisting to prevent unauthorized software, including dual-use remote admin tools, from being installed or executed.\n- Establish a policy requiring all business file exchanges to occur through sanctioned, monitored platforms rather than consumer messaging apps.\n- Deploy endpoint detection and response (EDR) solutions configured to alert on unusual remote management tool installations.\n\n**Detection measures:**\n- Monitor and alert on anomalous outbound connections originating from remote management software to unknown or unregistered management servers.\n- Enable centralized logging of script execution events (e.g., via Windows Event ID 4688 or PowerShell Script Block Logging) and review alerts regularly.\n- Conduct phishing simulation exercises that include messaging-app-based attack scenarios to improve employee detection skills.",[12,13,14,15,16,17,18,19,20,21,22],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 9: Email and Web Browser Protections","CIS Control 10: Malware Defenses","CIS Control 8: Audit Log Management","NIST SP 800-53 SI-3: Malicious Code Protection","NIST SP 800-53 CM-7: Least Functionality","NIST SP 800-53 AT-2: Security Awareness Training","NIST SP 800-53 AU-6: Audit Record Review and Analysis","MITRE ATT&CK T1219: Remote Access Software","MITRE ATT&CK T1204.002: User Execution – Malicious File","GDPR Article 32: Security of Processing (for organizations handling EU personal data on affected endpoints)","published","2026-06-23T00:20:23.229651+00:00","2026-06-23T00:20:22.936+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fwhatsapp-phishing-attack-uses-fake-business-docs-to-hack-pcs\u002F","whatsapp-phishing-attack-uses-fake-business-docs-to-hack-pcs-e7f163","WhatsApp phishing attack uses fake business docs to hack PCs",[31,37,43],{"id":32,"name":33,"slug":34,"description":35,"color":36},"1732a005-556e-411c-a9db-5edec3058571","Logging & Monitoring","logging-monitoring","Missing logs, no alerting, blind spots","#a855f7",{"id":38,"name":39,"slug":40,"description":41,"color":42},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":44,"name":45,"slug":46,"description":47,"color":48},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",[50],{"id":51,"date":52,"edition":53,"title":54,"audio_url":55},"a93b42f4-0053-44a0-86d3-a726afca1904","2026-06-23","morning","ThreatNoir Morning Brief — June 23","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-06-23\u002Fthreatnoir-morning-brief-2026-06-23.mp3"]