Hackers Exploit Familiarity to Spread Malware
This tactic relies on a simple weak point: trust. The malicious file is sent by someone you know, using their stolen account. There’s rarely any message—just the document. If you’re distracted or in a rush, you might not question it at all. Hackers count on the fact that most of us let our guard down when a familiar name pops up in a chat.
The scripts inside these files include comments in simplified Chinese. The notes reference Windows Update modules, helping the malware masquerade as a legitimate system component.
Connections to Known Spyware
Servers involved in these attacks have been linked to addresses associated with ValleyRAT and Gh0st RAT, both spyware families tied to Chinese-speaking cyber actors. Security firm Kaspersky has flagged these links, but stresses that the attribution is low-confidence.
Trust: The Unpatchable Vulnerability
The only weakness no update will ever fix is the trust you place in a familiar name on your messaging app.
This type of cyberattack preys on human reflexes. Even now in 2026, most people still don’t think twice before opening a file from someone they know. Ideally, everyone should verify—by phone or another method—before opening an unexpected attachment. But in reality, very few do.
Malicious file types like .vbs, .exe, .bat, .cmd, or .ps1 have no place in WhatsApp conversations. If you get one, stop. Don’t open anything unless you’re sure it’s legitimate. Sometimes, a healthy dose of skepticism is the best protection your phone will ever have.