Securelist Active Malware Campaign Distributes VBScript via Compromised WhatsApp Accounts
Article Content
- •Malware campaign targets WhatsApp Desktop and Web users with VBScript files.
- •Attackers use compromised accounts to distribute malicious attachments disguised as business documents.
- •The campaign has affected users in multiple countries, with Malaysia reporting the highest victim count.
In June 2026, a malware campaign was identified that spreads malicious VBScript files through WhatsApp direct messages. The campaign primarily targets users of WhatsApp Desktop and WhatsApp Web, with the highest number of victims in Malaysia. Attackers exploit compromised WhatsApp accounts to send deceptive messages containing attachments that appear as legitimate business documents, such as invoices and payment records. Once executed, the VBScript initiates a multi-stage infection chain that installs Remote Monitoring and Management (RMM) software, granting attackers remote access to the victims' systems. The campaign has affected users across multiple countries, including Brazil, India, Mexico, Singapore, the UK, Spain, Taiwan, Australia, Russia, and Vietnam. The threat actor's method of operation remains under investigation, with evidence suggesting extensive social engineering tactics. The campaign is still active as of the latest reports.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (29)
Following this threat?
Track Gh0st RAT in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Gambling Goblin Targets Brazilian Government Sites for SEO Fraud A Chinese-speaking cybercrime group, dubbed Gambling Goblin, has been targeting Brazilian government and educational institutions since mid-2025. This group is connected to the previously documented Earth Berberoka and is using compromised web servers to install malicious Apache modules. These modules reverse-proxy…
Surge in Exploited CVEs and Malware Activity in H1 2026 In the first half of 2026, Insikt Group reported 215 actively exploited CVEs, marking a 34% increase from the previous year. Notably, AsyncRAT emerged as the leading malware, with nearly 60,000 unique hashes. The report highlighted a significant rise in NFC-based Android attacks, which surged by 188%. Threat actors…