Financial Fraud via SMS and WhatsApp on the Rise: Advanced Smishing and Malicious .ZIP Attachments Target Mobile Banking
- Oswaldo Royett

- Jul 31
- 5 min read
The rapid evolution of digital banking has brought unprecedented convenience to millions of users worldwide. However, this shift has also attracted sophisticated cybercriminals who are constantly refining their methods to exploit vulnerabilities in mobile communication. In recent months, banking institutions and cybersecurity agencies have issued urgent alerts regarding a significant surge in advanced financial fraud conducted through SMS and WhatsApp. These campaigns are no longer limited to simple phishing links; they now involve complex multi-stage attacks and malicious file attachments designed to bypass traditional security measures and drain mobile banking accounts.
Ā
The Evolution of Smishing: Beyond Simple Links
Smishing, or SMS phishing, has transitioned from poorly worded messages to highly convincing lures that mimic official bank communications. Attackers leverage social engineering to create a sense of urgency, often claiming that a fraudulent transaction has been detected or that the user's account is at risk of being locked.
Ā
Feature | Traditional Smishing | Advanced Smishing |
Primary Lure | Generic "Click here" links | Urgent security alerts or "official" documents |
Payload | Credential harvesting websites | Malicious files (.zip, .lnk, .iso) |
Technical Complexity | Low (Single-stage) | High (Multi-stage infection chains) |
Evasion Tactics | Minimal | Heavy obfuscation and fileless execution |
These advanced tactics are designed to exploit the inherent trust users place in their mobile devices. Unlike emails, which are often filtered by sophisticated spam algorithms, SMS messages and WhatsApp chats are perceived as more personal and immediate, leading to higher click-through rates and successful compromises.
Ā
WhatsApp: The New Epicenter of Banking Malware
WhatsApp has become a primary vector for distributing banking Trojans, particularly in regions like Latin America and Africa. The platform's end-to-end encryption, while protecting user privacy, also provides a "blind spot" for many network-level security tools. Cybercriminals are now using compromised accounts to send malicious messages to the victim's contacts, significantly increasing the likelihood of the malware being executed.
Ā
"Cybercriminals are exploiting the social trust built within messaging apps. A message from a known contact is far more dangerous than an anonymous email because the recipient is less likely to question its legitimacy." ā Cybersecurity Research Brief, 2025
Ā
One of the most concerning trends is the use of self-propagating malware. Once a device is infected, the malware can hijack the WhatsApp session and automatically send copies of itself to all contacts and groups, creating a viral effect that can overwhelm entire organizations or communities in a matter of hours.
Ā
The Malicious .ZIP Trap: A Technical Breakdown
A prominent feature of recent campaigns is the distribution of malicious .ZIP attachments. These files often bear names like "Invoice," "Receipt," or "Health_Report" to entice the user to open them. Inside the archive, users typically find a Windows Shortcut (.LNK) file.
Ā
The Maverick and Coyote Campaigns
Research from major security firms such as KasperskyĀ and Trend MicroĀ has identified specific malware families like MaverickĀ and Coyote that utilize this method. These Trojans are specifically engineered to target financial institutions, with some variants monitoring access to over 60 different banking websites and cryptocurrency exchanges.
Ā
The typical infection chain follows these steps:
Initial Contact: The victim receives a WhatsApp message with a .ZIP file.
User Interaction: The message instructs the user to open the file on a PC, claiming it is for "security" or "proper visualization."
Execution: Opening the .LNK file inside the .ZIP triggers a hidden PowerShell command.
Payload Delivery: The command contacts a Command-and-Control (C2) server to download a .NET DLL.
Account Draining: The final payload monitors the user's activity. When a banking website is accessed, the malware uses "overlay" techniques to present a fake login screen, capturing credentials and one-time passwords (OTPs) in real-time.
Ā

Anatomy of an Attack: From Message to Theft
To understand the severity of these threats, it is essential to examine the sophisticated social engineering employed. A common message hook used in the MaverickĀ campaign is: "Visualization allowed only in computers. In case youāre using the Chrome browser, choose 'keep file' because itās a zipped file."
Ā
This specific instruction serves two purposes:
It moves the attack from the mobile device (where the user might have some protections) to a Windows PC, where the malware can gain deeper system access.
It guides the user through bypassing browser security warnings, making the malicious action seem like a necessary technical step.
Ā
Stage | Attacker Action | Victim Experience |
Delivery | Sends .ZIP via WhatsApp | Receives "Invoice" from a friend |
Trigger | Executes hidden PowerShell | Clicks the .LNK file |
Persistence | Installs in Startup folder | Nothing happens (seemingly) |
Theft | Overlays fake bank login | Enters credentials on a "real" site |
Once the credentials are stolen, the malware can also intercept SMS-based OTPs, allowing the attacker to perform unauthorized transfers and completely empty the victim's mobile banking account within minutes.
Ā
Global Institutional Alerts
Cybersecurity authorities worldwide are on high alert. The Cyber Security Authority (CSA)Ā of Ghana recently issued a public warning regarding a "WhatsApp ZIP Scam" hitting the region, where fake invoices are used to distribute malware. Similarly, Brazilian banking institutions have reported a massive surge in the MaverickĀ Trojan, with over 62,000 infection attempts blocked in a single 10-day period.
Ā

These alerts emphasize that the threat is no longer localized. The modular nature of modern malware allows attackers to quickly adapt their campaigns for different languages, regions, and banking systems.
Ā
How to Protect Your Financial Assets
In the face of these advanced threats, both individual users and enterprises must adopt a proactive security posture. The following recommendations are critical for preventing a compromise:
Ā
Never open unsolicited attachments: Even if a message comes from a known contact, verify its legitimacy through a separate channel (e.g., a phone call) before opening any files, especially .ZIP or .LNK files.
Beware of "PC-only" requests: Any message asking you to move a conversation from your phone to a computer to "view a file" is a major red flag.
Enable Multi-Factor Authentication (MFA): While malware can sometimes intercept OTPs, using app-based authenticators (like Google Authenticator or Microsoft Authenticator) is significantly more secure than SMS-based codes.
Keep Software Updated: Ensure your operating system and browsers are always up to date. Most modern browsers have built-in protections that can flag malicious downloads if they are not bypassed by the user.
Use Professional Security Software: Install reputable antivirus and anti-malware solutions on all devices, including mobile phones and personal computers.
Ā
The rise of advanced smishing and WhatsApp-based fraud represents a significant challenge for the financial sector and its customers. As cybercriminals continue to leverage automation, social engineering, and fileless malware, the traditional methods of defense are no longer sufficient. Staying informed about the latest tacticsāsuch as the malicious .ZIP trapāis the first and most crucial step in safeguarding your financial future. Banking institutions and cybersecurity experts will continue to monitor these threats, but the ultimate responsibility lies with the user to remain vigilant and skeptical of unsolicited digital communications.
Ā
References and Further Reading:
For a visual guide on identifying these scams, you can refer to educational resources such as this video breakdown of common WhatsApp scams.




Comments