logo

New WhatsApp Attack Chain Uses VBS Scripts, Cloud Downloads, and MSI Backdoors

ID: 9a48185c-030f-501f-844c-db4b35fb004c

STIX ID: report--9a48185c-030f-501f-844c-db4b35fb004c

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-04-02

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A Microsoft Defender–identified campaign uses WhatsApp to deliver malicious VBS files that create hidden folders, drop renamed legitimate Windows utilities, and download secondary scripts from cloud services (AWS S3, Tencent Cloud, Backblaze B2). The multi-stage attack bypasses UAC, modifies registry entries under HKLM\Software\Microsoft\Win, and installs unsigned MSI packages (Setup.msi, WinRAR.msi, LinkPoint.msi, AnyDesk.msi) to provide persistent remote access and potential data theft; recommended mitigations include blocking script hosts, monitoring renamed system utilities and cloud-hosted downloads, enabling EDR in block mode, and user training to avoid unexpected attachments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.