WhatsApp on Windows users targeted in new campaign, warns Microsoft

2026-04-01T20:51:53Z5a38794c16890a4b45228b69adf5b1791bd4146d73302b173f585d4fa4c9976e
axiosbrowser-extensioncisaclickfixcredential-theftfbiglassworminfiniti-stealerinfostealermacosnpmpersistencephishingremote-access-trojanrouter-securityscamssecurity-advisorysignalsocial-engineeringsoftware-supply-chainsupply-chainvenom-stealervirtual-phone-fraudwhatsappwindows

What happened

Collection of Malwarebytes Labs reports (late Mar–early Apr 2026) covering multiple active threats and security trends: Microsoft warns of an ongoing campaign targeting WhatsApp on Windows to achieve persistent access; an npm supply‑chain compromise of axios distributed a remote access trojan; macOS-focused threats (ClickFix abuse, Infiniti Stealer) and a new Apple mitigations; fake Avast scan pages installing Venom Stealer; GlassWorm distributing a malicious developer‑tools browser extension; and broader warnings from FBI/CISA about Signal/WhatsApp hijack social‑engineering campaigns. The set

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
malwarebytes_labs
Record identifier
5a38794c16890a4b45228b69adf5b1791bd4146d73302b173f585d4fa4c9976e
Enrichment time
2026-04-01T20:51:53Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.