logo

WhatsApp malware campaign delivers VBScript and MSI backdoors

ID: ad6c06ec-763d-5102-8515-f3bcffc56a28

STIX ID: report--ad6c06ec-763d-5102-8515-f3bcffc56a28

Feed Name: Microsoft Security

Threat Score
75/100

Date Published: 2026-03-31

Date Updated: 2026-04-28

Author: Microsoft Defender Security Research Team

...
...

Microsoft Defender observed a late-February-2026 WhatsApp-delivered VBS campaign that uses social engineering, renamed legitimate Windows utilities (LOLBAS), and payloads hosted on trusted cloud services (AWS, Tencent Cloud, Backblaze B2) to drop secondary VBS droppers, attempt UAC bypass and registry persistence, and ultimately install unsigned MSI installers (e.g., AnyDesk) for persistent remote access; the report provides multiple SHA-256 IOCs, cloud URLs, C2 domains, recommended mitigations, and hunting queries for detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.