WhatsApp VBScript Campaign Uses Fake Documents to Install ManageEngine RMM Tool
ID: 7ef6b7a6-42e0-512f-9d64-8adef5f6ae37
STIX ID: report--7ef6b7a6-42e0-512f-9d64-8adef5f6ae37
Feed Name: CosmicBytez Labs
Kaspersky researchers uncovered an active global campaign in which compromised WhatsApp accounts distribute obfuscated VBScript attachments that execute via WScript.exe, fetch secondary payloads, alter UAC settings, and install ManageEngine RMM Central to achieve stealthy persistent remote access; infrastructure overlaps (IP 202.61.160.201) and Chinese-language comments suggest a possible Chinese-speaking actor. The report describes execution variants across WhatsApp clients, lists indicators and high-risk file extensions, and recommends blocking/sandboxing messaging attachments and improving user awareness.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
