WhatsApp on Windows users targeted in new campaign, warns Microsoft
2026-04-01T20:51:53Z•5a38794c16890a4b45228b69adf5b1791bd4146d73302b173f585d4fa4c9976e
axiosbrowser-extensioncisaclickfixcredential-theftfbiglassworminfiniti-stealerinfostealermacosnpmpersistencephishingremote-access-trojanrouter-securityscamssecurity-advisorysignalsocial-engineeringsoftware-supply-chainsupply-chainvenom-stealervirtual-phone-fraudwhatsappwindows
What happened
Collection of Malwarebytes Labs reports (late Mar–early Apr 2026) covering multiple active threats and security trends: Microsoft warns of an ongoing campaign targeting WhatsApp on Windows to achieve persistent access; an npm supply‑chain compromise of axios distributed a remote access trojan; macOS-focused threats (ClickFix abuse, Infiniti Stealer) and a new Apple mitigations; fake Avast scan pages installing Venom Stealer; GlassWorm distributing a malicious developer‑tools browser extension; and broader warnings from FBI/CISA about Signal/WhatsApp hijack social‑engineering campaigns. The set
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- malwarebytes_labs
- Record identifier
- 5a38794c16890a4b45228b69adf5b1791bd4146d73302b173f585d4fa4c9976e
- Enrichment time
- 2026-04-01T20:51:53Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.