WhatsApp scam uses fake invoice as bait to hack devices
A new scam involving companies was identified by the cybersecurity company Kaspersky. Using WhatsApp as bait, criminals send messages through known contacts and collect outstanding invoices or payments.
Shared firsthand with CNN Money, the tactic is used as a way to increase the trust and credibility of the message, substantially increasing the likelihood that employees in financial and administrative departments will open the malicious attachments.
The files are sent in VBScript format, a configuration that executes codes and commands in Windows without necessarily requiring authorization, just by clicking directly on the document.
So, when opened, the device is activated and installs malware on the business computer, even bypassing the antivirus.
Once installed on the system, malware allows cybercriminals to take full control of the device remotely. This is dangerous as it gives scammers access to administrative capabilities to view screens, steal data, and monitor company activities invisibly.
Kaspersky did not identify this type of scam only in Brazil. According to the company, the use of different languages in the affected files allowed the identification of other countries involved in this type of scheme, such as Singapore, Taiwan, Vietnam and Malaysia, which record the highest volumes of cases.
"This shows that this is an operation planned to target several regions at the same time, which points to broad regional targeting, especially across Europe," explains Fabio Assolini, lead security researcher at Kaspersky.
Cyber scams like the one identified by the company are increasingly common.
A Datafolha survey in May, commissioned by the Brazilian Public Security Forum, showed that financial scams via the internet or cell phones affected around 26.3 million people in the last 12 months. Therefore, to avoid losses, it is important to protect yourself.
Losses from fraud on Pix grow 70% in 2024 | Market Opening
As a precaution, Assolini experts and the Kaspersky team recommend that companies instruct their employees to confirm the sending of invoices received via WhatsApp through other channels, even if the contact is known.
In addition, it is recommended that Information Technology professionals from each company block suspicious extensions such as:
- .vbs;
- .vbe;
- .exe;
- .bat;
- .cmd;
- .js;
- .ps1.
The company also emphasizes the importance of not opening files with these extensions, unless the legitimacy of the document has been independently verified directly with the sender.
In addition, robust security solutions are recommended to alert you to any unusual movement on devices.
See how to protect yourself from the "wrong Pix" scam
Source: CNN