Connect with us

NEWS

WhatsApp Still Hands Windows a Script Microsoft Wants Dead

MyCERT’s WhatsApp VBS alert hits Windows Desktop and Web, not phones, because VBScript is deprecated yet still on by default.

Published

on

MyCERT’s June 22, 2026 alert said a WhatsApp campaign was dropping.vbs files that install remote-access software on Windows PCs. The risk stops at Windows. iPhone, Android, macOS and Linux do not run those attachments as programs, and the mobile apps will not treat a.vbs file as something to execute.

The public advice is not to open the file. The reason the file is dangerous is older than WhatsApp: Windows still maps Visual Basic Script to Windows Script Host, even while Microsoft is retiring the language.

MyCERT’s June Alert Pins the Risk to Windows

CyberSecurity Malaysia’s incident team published MA-1464.062026, a June 22 alert on malicious VBScript sent through WhatsApp Desktop and WhatsApp Web. Attackers write to people on the chat app and push a script dressed as a financial or admin document. If the recipient opens it on Windows, the script starts the infection.

MyCERT said the payload silently installs a ManageEngine Endpoint Central remote-monitoring agent, which gives the attacker hands-on access. The agent installs as a Windows service so it survives a reboot. The same chain turns off security prompts, and a normal antivirus scan often fails to remove the agent because it looks like legitimate IT software.

Once that agent is up, MyCERT treats anything typed or shown on the machine as exposed, including passwords, banking PINs and one-time codes. The team’s advice if the file already ran is blunt: pull the cable or kill Wi-Fi, change every password from a clean device, and take the PC to someone who can strip an RMM agent. Reporting goes to MyCERT with a screenshot, a timestamp and the sender’s number. The Cyber999 desk takes calls on 1-300-88-2999 during business hours, or on +60 19 2665850 around the clock. Hours listed on this alert are Monday to Friday, 09:00 to 18:00 MYT.

The Attachment Looks Like a Bill

The lure is paperwork, not a hacking toy. Filenames borrow the language of invoices, debts and statements, then keep the.vbs extension that Windows knows how to run. MyCERT logged these recent samples:

NAMES MYCERT TIED TO THE LURE

  • Debt notice: Acknowledgment of Debt.vbs
  • Malay invoice: Sila semak bil anda..vbs
  • Account statement: December statement of account.vbs
  • Reconciliation file: Reconciliation.vbs

Kaspersky’s Global Research and Analysis Team, which published on the same date, saw the same trick in English, Portuguese, French, German and Malay, using invoices, bank statements, payment records and debt notices. The scripts also carry comments and metadata written to look like Windows Update parts. Compromised WhatsApp accounts send the file to existing contacts, so the chat often arrives from a name the recipient already trusts.

In this campaign, attackers are exploiting trust within messaging platforms by using compromised WhatsApp accounts to deliver malicious attachments that appear to originate from known contacts, making recipients far more inclined to engage with them. The file names are carefully disguised as routine business documents, such as invoices and payment notices, and localized across multiple languages to support broad targeting. Once opened, they trigger a staged infection chain that silently retrieves and executes additional malicious components from external infrastructure.

Fareed Radzi, security researcher, Kaspersky GReAT

A known contact is not a safe file. Replying is a bad idea for a second reason MyCERT spelled out: a reply tells the sender the number is live.

Why WhatsApp Desktop Opens a Script

This is not a no-click bug in the messenger. Kaspersky’s chain needs two user actions: download, then open. On WhatsApp Desktop for Windows, choosing Open in the chat is enough for the client to launch the script. Process trees in Kaspersky’s write-up show the desktop background process spawning WScript.exe from WhatsApp Desktop, with the.vbs sitting in the app’s Transfers folder under the user’s local packages directory.

WhatsApp Web is slower on purpose. The browser saves the file, and the user still has to open it from Downloads or from the download list, so the parent process is Explorer or the browser rather than the desktop client. In both cases Windows Script Host does the work, because.vbs is still wired to it.

WHERE THE CLICK ACTUALLY RUNS

Client What happens to a.vbs chat file Who launches it
WhatsApp Desktop on Windows Download, then Open in the chat can execute the script WhatsApp.Root.exe starts WScript.exe
WhatsApp Web on Windows Download first; the user must open the saved file Explorer or the browser starts WScript.exe
WhatsApp on iPhone or Android The file does not run as a Windows script Mobile apps will not treat.vbs as an executable
macOS or Linux Outside the campaign’s execution path No Windows Script Host

The first script, once running, creates a working folder under C:\Users\Public\Documents\, pulls more scripts from the attackers’ servers, and uses Windows Script Host again. A later stage fetches a zip that holds a preconfigured ManageEngine Endpoint Central installer. That is IT remote-control software used by real helpdesks, which is why scanners often shrug at it. One of the follow-up scripts also tampers with User Account Control so later steps can run with fewer prompts.

Defenders hunting this look for WScript.exe launched from a WhatsApp Desktop Transfers path, not for a custom virus name. The delivery also dies if Windows opens.vbs files in a text editor instead of Windows Script Host, because the chat app is only handing the file to whatever the OS already runs.

Malaysia Led an 11-Country Victim List

Kaspersky GReAT recorded victims in 11 countries: Malaysia, Brazil, India, Mexico, Singapore, the United Kingdom, Spain, Taiwan, Australia, Russia and Vietnam. The press note put the highest number of observed victims in Malaysia. That matches the Malay bill lure in MyCERT’s list and the local targeting in the June alert. How the WhatsApp accounts were stolen in the first place was still unknown in that research.

India’s Computer Emergency Response Team issued its own caution on June 25, 2026, telling people not to open unexpected attachments even when they come from a friend, colleague or relative. Maybank posted a Malay-language warning on July 8, 2026, telling customers not to tap a.vbs file that looks like an ordinary document, and pointing them to WhatsApp’s report tools or MyCERT’s Cyber999 line. Rajasthan Police and several of its district accounts were still circulating a WhatsApp VBS and ZIP caution on August 17, and again on August 31, 2026, with extra stress on WhatsApp Web users.

THE WARNING CALENDAR AFTER THE FIRST ALERT

  1. June 22, 2026: Kaspersky GReAT publishes the WhatsApp VBScript-to-RMM chain; MyCERT issues MA-1464.062026 the same day.
  2. June 25, 2026: CERT-In warns WhatsApp Desktop and Web users in India not to open unexpected attachments, including from known contacts.
  3. July 8, 2026: Maybank tells customers not to click.vbs files on WhatsApp and to call Cyber999 on 1-300-88-2999.
  4. August 17, 2026: Rajasthan Police posts a public caution against opening.vbs or.zip files from unknown or doubtful WhatsApp numbers, especially on WhatsApp Web.
  5. August 31, 2026: Pratapgarh Police repeats the same VBS and ZIP warning.

Those later posts do not prove a new Malaysian wave on those dates. They do show the same click path still being treated as live months after the June write-ups, which is what you would expect while Windows still executes the file type.

VBScript Is on a Kill List and Still On

Microsoft has been walking VBScript out of Windows in three phases. In the current phase it ships as a Feature on Demand and stays enabled by default on Windows 11 version 24H2. A later phase turns that feature off unless an admin puts it back. A last phase removes it from the image. Raina Sharma’s Windows IT Pro note on May 16, 2025, told organisations to find leftover.vbs use in logon scripts, scheduled tasks and old installers, then disable the capability on machines that no longer need it.

WHERE VBSCRIPT STANDS ON WINDOWS 11

Phase What Microsoft set What a WhatsApp.vbs click does
Phase 1 (current) Feature on Demand, on by default on Windows 11 24H2 WScript.exe can still run the attachment
Phase 2 (later) Feature off by default; admins can reinstall it The same file fails unless VBScript is added back
Phase 3 (unscheduled) Removed from future Windows releases No script engine for.vbs

Admins who have already confirmed that nothing legitimate needs the engine can strip it with DISM: Dism /Online /Remove-Capability /CapabilityName:VBSCRIPT~~~~. After that, processes that call cscript.exe or wscript.exe are blocked, and leftover scripts fail. Home users will not run that command. They still live on the default, which is why a chat attachment that would be inert on a phone becomes a remote-access installer on a Windows PC.

MyCERT cited one sample on VirusTotal under the hash 65662fbfee31784502f46a4ea3cf58a5146d6f6299b40391cd71c9fc67e3e621. The hash is a breadcrumb for analysts, not something a recipient should open to “check.”

What to Do If You Already Opened It

If the.vbs file already ran on a Windows PC, MyCERT says to treat the device as compromised, disconnect it from the internet at once, and change every password from a different, clean device. A standard antivirus pass is not enough, because the Endpoint Central agent installs as a service. The PC needs a specialist who knows how to remove remote-management software. Do not reply to the WhatsApp sender, and do not forward the file. Report the chat inside WhatsApp, then send MyCERT the screenshot, the time and the number.

MYCERT’S STEPS AFTER A BAD CLICK

  • Cut the link: Disconnect Wi-Fi or Ethernet so the remote agent cannot talk out.
  • Move accounts: From a clean phone or PC, change passwords and PINs used on the infected machine, and treat OTPs shown there as burned.
  • Skip a home scan: Bring the device to someone who can remove an RMM agent; a routine antivirus run often misses it.
  • File the report: Email cyber999 at cybersecurity.my, or call 1-300-88-2999 or +60 19 2665850, with the original message and the approximate time.

People who have not opened anything can still shrink the blast radius on a Windows machine they use for WhatsApp Web or Desktop: turn off auto-download so a script is not sitting in Downloads before anyone looks at the extension, and refuse.vbs,.vbe,.js,.ps1,.bat,.cmd and.exe attachments unless the sender confirms them on a second channel. Kaspersky’s note made the same file-type list. Maybank’s July 8 post put the consumer version in Malay, with the Cyber999 number on the card.

The messenger did not invent VBScript, and Microsoft has already told IT teams how to turn the engine off. Until that default flips, a WhatsApp bill that ends in.vbs is still a script Windows will run if someone opens it.

Harry is the editor of Oton Technology, an independent site he owns and edits, covering the part of technology that people actually have to act on. After ten years in journalism, first reporting and then editing, he works from primary material by habit: the advisory rather than the write up of it, the filing rather than the press release, the changelog rather than the launch video. Every figure in an article carries its source and its date, and where a number comes from a vendor or an analyst model rather than a count, he says so plainly instead of letting it stand as established fact. What he leaves out is anything he could not verify himself, which on a beat full of unnamed supply chain claims removes a great deal. That standard applies across all the sections the site publishes for an international audience, from artificial intelligence and security to phones, computers, gaming, crypto and the software businesses depend on. He corrects errors in the open and labels them, because a site that hides its mistakes is asking readers to trust the rest on nothing.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending