Don't open that WhatsApp message, Microsoft warns
ID: 182b1dc9-2663-5d7d-b8ef-62b4e4fe4368
STIX ID: report--182b1dc9-2663-5d7d-b8ef-62b4e4fe4368
Feed Name: The Register (Security)
### Executive summary A multi-stage campaign beginning in late February uses social-engineered WhatsApp messages to trick victims into running VBS attachments; the scripts create hidden folders in C:\ProgramData, drop renamed legitimate Windows utilities (e.g., curl.exe as netapi.dll, bitsadmin.exe as sc.exe) to fetch secondary VBS payloads from cloud services, attempt UAC elevation for persistence, and install unsigned MSI packages (Setup.msi, WinRAR.msi, LinkPoint.msi, AnyDesk.msi) that grant remote access for data theft, further malware deployment, or ransomware.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
