logo

WhatsApp Under Siege: Microsoft Uncovers Global VBS Malware Campaign

ID: 0e20dece-01f9-58b4-8e3b-1e740c7eb798

STIX ID: report--0e20dece-01f9-58b4-8e3b-1e740c7eb798

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-04-07

Date Updated: 2026-04-23

Author: Ddos

...
...

Microsoft Defender researchers detail a widespread 2026 WhatsApp-based malware campaign that delivers malicious VBS scripts which drop renamed Windows utilities and retrieve secondary payloads from trusted cloud platforms (AWS S3, Tencent Cloud, Backblaze) to evade detection; the malware repeatedly attempts UAC elevation, installs MSI packages for persistence and enables remote access, while defenders are advised to block/limit script hosts, monitor cloud downloads and registry tampering, and inspect PE OriginalFileName metadata for anomalies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.