Skip to content
Quick Heal Technologies Limited Warns of Evolving WhatsApp Malware Campaign Targeting Finance Teams, Executives and Business Users

Quick Heal Technologies Limited Warns of Evolving WhatsApp Malware Campaign Targeting Finance Teams, Executives and Business Users

www.ncnonline.net September 15, 2026

Quick Heal Technologies Limited , a global provider of cybersecurity solutions, issued a warning on an ongoing WhatsApp-based malware campaign targeting finance teams, senior executives, chartered accountants and individual business users. The campaign is spreading through compromised WhatsApp accounts and is evolving rapidly, with attackers adopting new file formats and evasion methods to bypass security controls and establish persistent access to victims’ devices.

Investigation conducted by the company’s researchers at Seqrite Labs, India’s largest malware analysis facility, shows that the campaign relies on trust rather than unsolicited messages from unknown numbers. Once a WhatsApp account is compromised, attackers use it to forward malicious files to the account holder’s existing contacts. Because the messages appear to come from a known colleague, client, friend or business associate, recipients may be more likely to open the attachment without independently verifying it.

The attackers are using finance- and compliance-themed filenames to create urgency and familiarity. Malicious attachments have been disguised as routine business documents, including “Financial Report,” “Account Statement,” “Outstanding Payment List” and “Debt Confirmation.” Some variants also impersonate urgent communications from regulatory institutions, including the Reserve Bank of India and the Ministry of Corporate Affairs, in an effort to pressure recipients into opening the files immediately.

The campaign evolves through several delivery methods. It initially spreads through malicious Visual Basic Script files, or .vbs files, sent directly through WhatsApp. The attackers later shifted to ZIP archives carrying an executable and a supporting malicious file, using DLL sideloading to make a legitimate-looking program load harmful code. The company cautions that .img and .vhd files are not ordinary photographs or documents. When a user double-clicks one of these files, Windows treats it like a newly connected disk drive, potentially exposing an executable and concealed malicious components. Users should treat an unexpected .img or .vhd attachment with the same caution they would apply to an unknown .exe file.

In its latest form, the malware uses DLL sideloading and a Bring Your Own Vulnerable Driver (BYOVD) technique to undermine endpoint defenses. BYOVD involves installing legitimate, digitally signed drivers that contain known vulnerabilities; attackers can misuse these trusted drivers to disable or impair antivirus tools before deploying their payload. Once security controls have been weakened, the campaign installs legitimate remote monitoring and management tools, which are configured with password and self-protection mechanisms, making them more difficult for victims and IT teams to identify and remove. This can give attackers persistent, hands-on access to the infected system, including the ability to execute commands, move files and monitor activity.

Infected systems can use an active WhatsApp Web session to automatically forward the malicious file to the victim’s contacts, allowing the campaign to propagate further through trusted social and professional networks. The self-propagating feature expands the risk from an individual compromise into a wider business and supply-chain concern, particularly where employees, vendors, customers and finance functions communicate frequently over WhatsApp.

Quick Heal Technologies Limited recommends that organisations and individuals never open an unexpected file received on WhatsApp or any messaging platform, even if it appears to come from a known . Recipients should verify the attachment through a separate channel, such as a phone call, rather than replying in the same conversation. Users should also routinely review WhatsApp’s Linked Devices settings and log out of web or desktop sessions they do not recognise or no longer use.

The company also advises organisations to maintain updated endpoint protection, prohibit unauthorised remote-access software, monitor for suspicious driver installations and alert employees to the risks posed by finance-themed attachments and pressure-based messages. If a compromise is suspected, users should immediately log out of WhatsApp-linked devices, disconnect the affected device from the network, inform their IT or security team, and warn their contacts not to open files sent from their number.

Covered By: NCN MAGAZINE / Quick Heal

If you have an interesting Article / Report/case study to , please get in touch with us at [email protected] , [email protected] , 9811346846 / 9625243429

Honoured to inaugurate the Made in India: Champions of Bharat Brand Book - Bharatpreneurs and felicitate outstanding entrepreneurs, manufacturers and brands during the launch and awards ceremony held at Bharat Mandapam, New Delhi, as part of the ongoing Bharat Vyapar Mahotsav… pic.twitter.com/fPRDUdMSFi — Praveen Khandelwal (@PKhandelwal_MP) August 14, 2026

Honoured to inaugurate the Made in India: Champions of Bharat Brand Book - Bharatpreneurs and felicitate outstanding entrepreneurs, manufacturers and brands during the launch and awards ceremony held at Bharat Mandapam, New Delhi, as part of the ongoing Bharat Vyapar Mahotsav… pic.twitter.com/fPRDUdMSFi

Extracted Entities

Attack Types (1)

Countries (1)

Domains (1)

Industries (1)

Platforms (2)