Theregister WhatsApp Malware Campaign Exploits VBS Files for Remote Access
Article Content
- •Attackers use WhatsApp to deliver malicious VBS files, leveraging social engineering.
- •The campaign employs living-off-the-land techniques, using legitimate Windows tools to evade detection.
- •Malicious MSI packages are installed to maintain persistent access and control over compromised systems.
A new malware campaign targeting WhatsApp users has been identified, utilizing malicious Visual Basic Script (VBS) files to gain persistent access to victims' systems. Microsoft reported that the campaign began in late February 2026, employing social engineering tactics to trick users into executing these scripts. Once activated, the VBS files create hidden directories and deploy renamed legitimate Windows utilities to blend in with normal system activity. The attackers then download additional payloads from trusted cloud services like AWS and Tencent Cloud, ultimately installing malicious Microsoft Installer (MSI) packages to maintain control over the infected devices. The campaign's stealthy approach, relying on living-off-the-land techniques, makes it difficult for traditional security measures to detect the malicious activity. Microsoft has recommended using Defender for Endpoint in block mode to mitigate the risks associated with this attack.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (14)
Following this threat?
Track AWS in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
BlueMoon Exploit Kit Targeting Chrome and Windows by Multiple State Actors A new exploit kit named BlueMoon has been rapidly adopted by at least four espionage groups, primarily linked to China, exploiting vulnerabilities in Google Chrome and Microsoft Windows. The first observed use of BlueMoon was on August 28, 2026, by the China-aligned threat actor TA412, with subsequent adoption by…