Microsoft Warns of WhatsApp Attachments Spreading Backdoor on Windows PCs
ID: 27aebb3a-f35d-5aeb-a744-2142f9ed1016
STIX ID: report--27aebb3a-f35d-5aeb-a744-2142f9ed1016
Feed Name: HackRead
Microsoft Defender researchers warn of an active social-engineering campaign (delivered via WhatsApp) that uses a Visual Basic Script attachment to execute a chain of living-off-the-land techniques: creating hidden ProgramData folders, renaming legitimate Windows tools (e.g., curl.exe to netapi.dll, bitsadmin.exe to sc.exe), fetching payloads from trusted cloud services (AWS S3, Tencent Cloud, Backblaze B2), disabling UAC via registry changes, and installing unsigned installers (WinRAR.msi, Setup.msi, AnyDesk.msi) to establish remote access and exfiltrate data. The report highlights how trust in messaging apps and common tools enables the attack and cautions about using personal apps on work devices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
