WhatsApp message from a known contact delivers a fake invoice that installs malware
Fraudsters compromise a real WhatsApp contact then send fake invoices or bank documents as ZIP files (.vbs, .exe, .dll inside). Opening the file installs remote-access malware on Windows, stealing bank credentials and UPI passwords.
Also known as: WhatsApp invoice malware, WhatsApp VBScript virus, fake bank statement WhatsApp malware, WhatsApp ZIP attachment scam, CERT-In WhatsApp malware advisory
Already happened to you? Do this in the next few minutes
Call 1930 now- 1 Call 1930 — the national cyber-crime helpline — right now. The sooner you report, the better the chance of freezing the money before it moves.
- 2 Call your bank to freeze the account and block the card immediately. Use the number printed on your card, never a number from the message or caller.
- 3 File a report at cybercrime.gov.in and keep every message, screenshot, and transaction ID.
- ! If you installed any "support", "server", "refund", or remote-access app at their request (AnyDesk, TeamViewer, Quick Support, etc.): disconnect the internet now, then run free SeraphSecure (https://www.seraphsecure.com) to detect and remove it.
What to do right now
- 1 Do NOT open any ZIP file sent via WhatsApp, even from a known contact, unless you explicitly requested it
- 2 If you already opened the file: disconnect your device from the internet immediately, then run a full antivirus scan
- 3 From a separate clean device, change your internet banking, UPI, and email passwords immediately
- 4 Alert your bank by phone to watch for or freeze suspicious transactions
- 5 Warn the contact whose account was used — their WhatsApp or device may be compromised
- 6 If you installed any 'support' or 'server' or 'refund app' or remote-access app at the scammer's request (AnyDesk, TeamViewer, Quick Support, etc.), run free SeraphSecure (https://www.seraphsecure.com) to detect and remove it.
- 7 Report at https://cybercrime.gov.in or call 1930 (national cyber helpline).
Was remote-access software installed?
If a scammer asked you to install AnyDesk, TeamViewer, Quick Support, or any remote-access app, your device may still be compromised.
Run SeraphSecure to detect and remove it →Red flags
- ⚠ A known WhatsApp contact sends an unexpected file — especially a ZIP containing .vbs, .exe, or .dll files — claiming it is an invoice, payment confirmation, or bank statement
- ⚠ You never requested such a document; the message may say 'Please find attached invoice' or 'Check your payment receipt'
- ⚠ After opening the file, a black command window flashes briefly or nothing visible happens — that is the malware running silently
- ⚠ Your antivirus may flag it as 'Worm:VBS', 'Trojan.Downloader', or similar
- ⚠ The WhatsApp account sending it belongs to a real person you know — whose phone has been compromised or whose account has been hijacked
Sources
- Free Press Journal / CERT-In — New WhatsApp malware alert: VBScript worm spreads via fake invoices and bank statements (July 7, 2026)
- The420.in / CyberDost — WhatsApp malware advisory: EXE and DLL files disguised as invoices; Windows users at risk (July 20, 2026)
- NewsBytesApp — CERT-In warns of WhatsApp malware campaign spreading via fake invoices
- Pune Pulse — Cyber alert: WhatsApp being used to spread malware via fake invoices and bank statements
- Windows News — CERT-In advisory: WhatsApp malware spreading via invoices targets Indian users