logo

WhatsApp VBScript Campaign Uses Fake Documents to Install ManageEngine RMM Tool

ID: 7ef6b7a6-42e0-512f-9d64-8adef5f6ae37

STIX ID: report--7ef6b7a6-42e0-512f-9d64-8adef5f6ae37

Feed Name: CosmicBytez Labs

Threat Score
75/100

Date Published: 2026-06-23

Date Updated: 2026-06-24

...
...

Kaspersky researchers uncovered an active global campaign in which compromised WhatsApp accounts distribute obfuscated VBScript attachments that execute via WScript.exe, fetch secondary payloads, alter UAC settings, and install ManageEngine RMM Central to achieve stealthy persistent remote access; infrastructure overlaps (IP 202.61.160.201) and Chinese-language comments suggest a possible Chinese-speaking actor. The report describes execution variants across WhatsApp clients, lists indicators and high-risk file extensions, and recommends blocking/sandboxing messaging attachments and improving user awareness.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.