Summary of this article
Attackers are using VBS, ZIP, IMG and VHD files to spread WhatsApp malware.
Compromised accounts send convincing financial or regulatory files to existing contacts.
Users should avoid unexpected attachments, verify senders and check linked devices regularly.
WhatsApp is being used to spread malicious files through compromised accounts, putting finance teams, executives, chartered accountants, and business users at risk. Attackers are changing the files used in these attacks, making some of them difficult to recognise as potential threats, cybersecurity firm Quick Heal has said in an article on its website.
The malware has been seen in VBS files, ZIP archives and, more recently, IMG and VHD files. According to Quick Heal, the attacks have evolved since August 2026 with attackers changing file formats and using techniques to evade antivirus protection.
How Is The Malware Spreading On WhatsApp?
The malicious file is sent from a compromised WhatsApp account to the account holder’s existing contacts. The person whose account has been compromised may not realise that the file is being sent from their account.
The files can be given names linked to financial or business activities, such as financial reports, account statements, outstanding payment lists, or debt confirmations. Some have also been made to appear like urgent communications from regulators, including the Reserve Bank of India (RBI) and the Ministry of Corporate Affairs (MCA). This means a recipient may recognise the sender while also seeing a file that appears relevant to their work or finances.
What Files Are Being Used?
The malware has changed its delivery method over time. It initially used VBS script files before moving to ZIP archives containing malicious components. The latest versions use IMG and VHD files. Despite the word image in the file extension, these are not photo files like JPG or PNG. They are disk image formats that can be mounted by Windows as virtual drives and can contain programs.
Once the malicious file runs, it instals a remote monitoring and management tool or, in some cases, a backdoor Trojan, allowing attackers to gain access to the device. The malware also uses a technique known as Bring Your Own Vulnerable Driver (BYOVD). It involves using legitimate but vulnerable signed drivers to interfere with antivirus protection.
Quick Heal said that an infected device can also use an active WhatsApp Web session to automatically send the malicious file to the victim’s contacts, helping the malware spread further.
How Can WhatsApp Users Stay Safe?
Users should avoid opening unexpected files received on WhatsApp, even when they appear to come from a known contact. If an attachment seems unusual, confirm with the sender through a separate channel before opening it. ZIP, IMG and VHD files require particular caution, especially when their names refer to payments, account records or regulatory notices.
Users should also keep antivirus and endpoint protection software updated and regularly check WhatsApp’s Linked Devices section for unfamiliar sessions.







