Close Menu
Tech Nova Mindset – Empower Innovation and Forward Thinking

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    This Week’s Awesome Tech Stories From Around the Web (Through August 8)

    August 8, 2026

    How to Disable Gemini in Gmail and Google Docs

    August 8, 2026

    How ideas of a vast censorship network moved from the online fringe to Trump policy

    August 8, 2026
    Facebook X (Twitter) Instagram
    Trending
    • This Week’s Awesome Tech Stories From Around the Web (Through August 8)
    • How to Disable Gemini in Gmail and Google Docs
    • How ideas of a vast censorship network moved from the online fringe to Trump policy
    • The Pivot From Tech Expert to Organizational Leader
    • Scientists Used AI to Create 16 New Viruses
    • The Download: a censorship conspiracy theory and the first virus created by AI
    • V2X Technology Gets a 5G Cellphone Network Solution
    • AI may respond differently to bosses and subordinates
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    • Home
    • Gadgets
    • Reviews
    • Tech News
    • Future Tech
    • AI & Robotics
    • How-To Guides
    • More
      • Cybersecurity
      • Startups & Innovation
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    Home»Cybersecurity»Don’t open that WhatsApp message, Microsoft warns • The Register
    Cybersecurity

    Don’t open that WhatsApp message, Microsoft warns • The Register

    kirklandc008@gmail.comBy kirklandc008@gmail.comMarch 31, 2026No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Don't open that WhatsApp message, Microsoft warns • The Register
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Be careful what you click on. Miscreants are abusing WhatsApp messages in a multi-stage attack that delivers malicious Microsoft Installer (MSI) packages, allowing criminals to control victims’ machines and access all of their data.

    The campaign began in late February, we’re told, and the attack chain starts with a WhatsApp message that delivers malicious Visual Basic Script (VBS) files. We’re not sure exactly how the social engineering part of the scam works – we’ve asked Redmond for additional details and will update this story if we receive any. 

    The Register also reached out to Meta-owned WhatsApp for comment and did not hear back.

    But somehow the attacker tricks the message recipient into executing the malicious file on their system. They likely do this using a compromised WhatsApp session so that the message appears to come from one of the victim’s existing contacts. Or they blast users with a lure that contains a sense of urgency, prompting the recipient to open the file in a rush.

    Once it’s executed, the malicious script creates hidden folders in C:\ProgramData and drops renamed versions of legitimate Windows utilities – for example, curl.exe renamed as netapi.dll and bitsadmin.exe as sc.exe.

    Using legitimate Windows tools for evil purposes allows attackers to blend in with normal network activity – defenders call this “living off the land” – but the miscreants did make a mistake in renaming these binaries. 

    “Notably, these renamed binaries retain their original PE (Portable Executable) metadata, including the OriginalFileName field which still identifies them as curl.exe and bitsadmin.exe,” Microsoft’s researchers wrote in a Tuesday blog. “This means Microsoft Defender and other security solutions can leverage this metadata discrepancy as a detection signal, flagging instances where a file’s name does not match its embedded OriginalFileName.”

    The crims use the renamed binaries to download secondary VBS payloads (auxs.vbs, 2009.vbs) from trusted cloud services including AWS, Tencent Cloud, and Backblaze B2. Again, this makes it more difficult to distinguish between normal enterprise activity and malicious downloads.

    Then the malware alters the User Account Control (UAC) settings, attempting to launch cmd.exe with elevated privileges until it either succeeds, meaning the malware will survive a system reboot, or the process is forcibly terminated. 

    Finally, the attackers deploy malicious MSI installers, and Microsoft says that these include Setup.msi, WinRAR.msi, LinkPoint.msi, and AnyDesk.msi. Once again, the baddies use real tools like AnyDesk – not custom malware – to hide in plain sight. 

    However, none of the final payloads are signed, and this should be another indication to defenders that they are dealing with malware, not legit enterprise software.

    These installers give the attackers remote access to victims’ systems so they can steal data, deploy more malware – such as ransomware – on compromised systems, or use the infected machines as part of a larger network from which to launch other attacks.

    While Microsoft’s blog includes several recommendations directing people to use their security products to avoid this type of compromise, one vendor-neutral tip that we especially like involves educating users on how to spot social engineering campaigns. 

    “Train employees to recognize suspicious WhatsApp attachments and unexpected messages, reinforcing that even familiar platforms can be exploited for malware delivery,” Redmond advises. ®

    Dont Message Microsoft open Register warns WhatsApp
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    kirklandc008@gmail.com
    • Website

    Related Posts

    OpenAI’s Browser Could Be Hijacked to Spam Your WhatsApp Contacts

    August 6, 2026

    OpenAI Didn’t Notice Its AI Agents Using a Message Board to Plan Their Hacking Spree

    August 6, 2026

    Nvidia’s Open Source Alliance Snubs OpenAI and Anthropic

    July 30, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Nothing CEO says phone prices are going to keep going up

    June 12, 20267 Views

    Google DeepMind Plans to Track AGI Progress With These 10 Traits of General Intelligence

    March 21, 20263 Views

    The AirPods 4 and Lego’s brick-ified Grogu are our favorite deals this week

    October 12, 20253 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Recent Posts
    • This Week’s Awesome Tech Stories From Around the Web (Through August 8)
    • How to Disable Gemini in Gmail and Google Docs
    • How ideas of a vast censorship network moved from the online fringe to Trump policy
    • The Pivot From Tech Expert to Organizational Leader
    • Scientists Used AI to Create 16 New Viruses

    This Week’s Awesome Tech Stories From Around the Web (Through August 8)

    August 8, 2026

    How to Disable Gemini in Gmail and Google Docs

    August 8, 2026

    How ideas of a vast censorship network moved from the online fringe to Trump policy

    August 8, 2026

    The Pivot From Tech Expert to Organizational Leader

    August 7, 2026
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 TechNovaMindset. Designed by By Pro.

    Type above and press Enter to search. Press Esc to cancel.