New Malware Attack Via WhatsApp Attacking Windows System to Enable Remote Access For Attackers
ID: 19ccd69b-513f-5228-981f-1a79c227048d
STIX ID: report--19ccd69b-513f-5228-981f-1a79c227048d
Feed Name: cybersecurityNews.com
Threat Score
## Executive Summary: A widespread WhatsApp-based malware campaign observed since June 2026 distributes malicious VBScript attachments that silently download and install a pre-configured ManageEngine Endpoint Central agent on Windows systems, granting attackers persistent remote access; victims span more than a dozen countries (notably Malaysia), and the report provides extensive IoCs (IPs, domains, MD5 hashes) and low-confidence attribution to a Chinese-speaking operator.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
