Microsoft warned on March 31, 2026 of an ongoing social engineering campaign using WhatsApp messages as an attack vector. The attackers send messages with links to malicious MSI installation packages.
How the Attack Works
The messages disguise themselves as business communications — invoices, contract documents or invitations. The link leads to an MSI package that installs a backdoor. The packages are often signed or use look-alike domain names to appear legitimate.
Why WhatsApp
WhatsApp is used for business communication in many companies — especially in the DACH region — even though it is not designed for that purpose. End-to-end encryption means that security tools cannot scan the content of messages. For attackers, this is ideal: the channel is trusted and invisible to corporate security.
Countermeasures
Microsoft recommends employee training as the primary defense. Technical measures: restrict MSI installation on managed devices, application whitelisting, and filtering WhatsApp links in MDM solutions (Mobile Device Management) where possible.
Source: Microsoft Security Blog (31.03.2026), The Register.