According to the Internet Storm Center, the threat actors initiate the data theft scheme by sending out invitations to view photos on WhatsApp. If a user clicks on the link, he or she will download whatsapp.exe, a malware dropper file. This launches what looks like an Adobe PDF Reader, but those who install it wind up activating md1.exe and md0.exe, which are bundled in a .cab file.




Whatsapp .cab File For Windows Mobile 6.5