Microsoft Warns of WhatsApp-Delivered VBS Malware Hijacking Windows via UAC Bypass
ID: 5819ecbe-1442-52e6-a6a1-8a57920896e6
STIX ID: report--5819ecbe-1442-52e6-a6a1-8a57920896e6
Feed Name: The Hacker News
Microsoft warns of an active campaign (starting late February 2026) that uses WhatsApp-delivered malicious VBS files to drop hidden folders and renamed legitimate Windows utilities, retrieve secondary payloads from trusted cloud providers (AWS S3, Tencent Cloud, Backblaze B2), perform UAC bypass and registry modifications, and install unsigned MSI packages (including legitimate remote-access tools like AnyDesk) to maintain persistent remote access and enable data exfiltration or further malware deployment.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
