Windows Script Host - Tool

Threat entity extracted from intelligence sources

Frequency
15
occurrences
First Seen
January 12, 2026
Last Seen
September 4, 2026

Related Threat Clusters

  • Rogue ScreenConnect Clients Spread Malware Like a Worm

    Huntress has reported a wave of rogue ScreenConnect installations that spread malware across Windows systems without further action from victims or attackers. This self-propagating attack chain, resembling a worm,…

    10 articles · Updated September 3, 2026
  • New Remcos RAT Campaign Exploits CVE-2017-11882 via Phishing

    A new phishing campaign distributing a variant of the Remcos RAT has been identified, targeting Microsoft Windows users. The attack utilizes a fake shipping document to deliver a malicious Word file that exploits…

    2 articles · Updated May 29, 2026
  • Global Phishing Campaign Uses Lua Loader Disguised as TrueType Font Files

    Since late March 2026, a large-scale phishing campaign has been observed utilizing disguised TrueType Font (.ttf) files to deliver Lua-based loaders and various malware, including Agent Tesla and Remcos. The attackers…

    5 articles · Updated July 16, 2026
  • Active Malware Campaign Distributes VBScript via Compromised WhatsApp Accounts

    In June 2026, a malware campaign was identified that spreads malicious VBScript files through WhatsApp direct messages. The campaign primarily targets users of WhatsApp Desktop and WhatsApp Web, with the highest number…

    29 articles · Updated June 22, 2026
  • IT Support Impersonation via Microsoft Teams Leads to Domain Access

    A human-operated intrusion campaign has been identified, exploiting Microsoft Teams for IT support impersonation. Threat actors socially engineer users into granting remote access, allowing them to deploy a malicious…

    4 articles · Updated September 4, 2026
  • Fileless PureLog Stealer Campaign Exploits Compromised Websites

    A sophisticated cyber campaign is leveraging compromised websites and a malicious JavaScript file named transcript.pdf.js to deploy PureLog Stealer, a .NET-based infostealer. The attack uses a fileless infection method,…

    5 articles · Updated July 3, 2026
  • Phishing Campaign Exploits Google Storage to Deploy Remcos RAT

    A phishing campaign has been detected that exploits Google Cloud Storage to deliver the Remcos remote access trojan (RAT). Attackers host a fake Google Drive login page on the legitimate domain storage.googleapis.com,…

    6 articles · Updated April 9, 2026
  • Gootloader Malware Evades Detection with Malformed ZIP Archives

    Gootloader, a malware loader used for initial access in ransomware attacks, employs a malformed ZIP archive to evade detection. This archive, which contains a JScript file, causes common unarchiving tools like 7zip and…

    5 articles · Updated January 16, 2026
  • PURELOGS Infostealer Campaign Utilizes Weaponized PNG Files

    A sophisticated attack campaign has been identified where the PURELOGS infostealer is delivered via weaponized PNG files. The campaign initiates with phishing emails disguised as pharmaceutical invoices, leading to the…

    2 articles · Updated January 21, 2026
  • Cyber Threat Landscape in Finance Sector: Key Trends Identified

    The financial sector, including banks and cryptocurrency platforms, is facing a complex cyber threat landscape. This sector's heavy reliance on digital infrastructure makes it a prime target for both financially…

    3 articles · Updated January 28, 2026

Recent Intelligence Reports

  • IT Support Impersonation Turns a Teams Chat Into Domain — Cybersecurity-Insiders · September 4, 2026
  • Hijacked ScreenConnect Installs Are Spreading Malware Like a Worm, Huntress Warns — Itsecurityguru · September 3, 2026
  • Impersonating IT support: how threat actors turn a remote session into enterprise — Blogs.Microsoft · September 2, 2026
  • Fake TTF files deliver stealthy malware in global phishing campaign — Csoonline · July 17, 2026
  • Phishing Campaign Hides Lua Loader as TrueType Font File — Infosecurity-Magazine · July 16, 2026
  • Fileless Malware Abuses Google Blogspot to Deploy Infostealer in Memory — Infosecurity-Magazine · July 1, 2026
  • Kaspersky uncovers a new massive campaign spreading malware via WhatsApp — Kaspersky · June 22, 2026
  • Deceptively Sweet: DonutLoader Reloaded in a modern Remcos RAT Infection — Feeds.Feedburner · May 29, 2026

CVSS v3.1 Breakdown