logo

WhatsApp Attack Chain Delivers VBS, Cloud Payloads, MSI Backdoor

ID: 9dbffa23-e6e3-589f-861e-a63d0f945ffd

STIX ID: report--9dbffa23-e6e3-589f-861e-a63d0f945ffd

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-04-02

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Microsoft observed a late-February 2026 campaign delivering VBS attachments via WhatsApp that drop secondary VBS payloads from legitimate cloud services and use renamed living-off-the-land binaries to fetch and install unsigned MSI backdoors; the actors attempt UAC bypass and registry tampering to gain persistent elevated access, and defenders are advised to monitor PE metadata, command-line usage, UAC-related registry changes, and suspicious downloads from cloud providers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.