WhatsApp on Windows users targeted in new campaign, warns Microsoft
ID: 7f95a6e7-314a-532f-99cf-3d5d614c94a4
STIX ID: report--7f95a6e7-314a-532f-99cf-3d5d614c94a4
Feed Name: Malwarebytes Blog
Threat Score
Microsoft researchers discovered a WhatsApp attachment campaign that delivers .vbs files which, when executed by a user, copy and rename legitimate Windows tools to download additional scripts and an unsigned MSI installer that sets up remote-access payloads. The attack relies on social engineering, living-off-the-land abuse of built-in tools, cloud-hosted payload delivery to blend into normal traffic, and persistence via UAC/registry modifications.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
