logo

Don't open that WhatsApp message, Microsoft warns

ID: 182b1dc9-2663-5d7d-b8ef-62b4e4fe4368

STIX ID: report--182b1dc9-2663-5d7d-b8ef-62b4e4fe4368

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2026-03-31

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

### Executive summary A multi-stage campaign beginning in late February uses social-engineered WhatsApp messages to trick victims into running VBS attachments; the scripts create hidden folders in C:\ProgramData, drop renamed legitimate Windows utilities (e.g., curl.exe as netapi.dll, bitsadmin.exe as sc.exe) to fetch secondary VBS payloads from cloud services, attempt UAC elevation for persistence, and install unsigned MSI packages (Setup.msi, WinRAR.msi, LinkPoint.msi, AnyDesk.msi) that grant remote access for data theft, further malware deployment, or ransomware.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.