WScript - Tool

Threat entity extracted from intelligence sources

Frequency
3
occurrences
First Seen
January 26, 2026
Last Seen
June 18, 2026

WScript is a tool tracked across 3 threat clusters and 3 intelligence report mentions on ThreatCluster. First observed January 26, 2026; most recent activity June 18, 2026.

Related Threat Clusters

  • Vidar Infostealer Adopts Fileless Techniques Using JPEG and TXT Payloads

    The Vidar infostealer has evolved into a sophisticated multi-stage attack framework that utilizes fileless techniques to evade detection. Attackers embed malicious payloads within JPEG images and TXT documents,…

    9 articles · Updated April 28, 2026
  • New Crypto Clipper Malware Uses USB and Tor for Stealthy Attacks

    Microsoft has identified a new cryptocurrency-stealing malware named Crypto Clipper, active since February 2026. This malware spreads primarily through malicious Windows shortcut files (.lnk) on USB drives, targeting…

    28 articles · Updated June 18, 2026
  • PeckBirdy Framework Targets Gambling Industries in China

    PeckBirdy is a JScript-based command-and-control framework utilized by China-aligned APT groups to exploit LOLBins. Since 2023, it has been deployed against gambling industries and Asian government entities, delivering…

    7 articles · Updated January 27, 2026

Recent Intelligence Reports

  • Microsoft Warns of New Crypto Clipper Malware That Acts Like a Worm — Coinedition · June 18, 2026
  • Vidar infostealer evolves, uses image files for stealthy attacks | brief — Scworld · April 28, 2026
  • PeckBirdy: A Versatile Script Framework for LOLBins Exploitation Used by China — Feeds.Trendmicro · January 26, 2026

CVSS v3.1 Breakdown