logo

WhatsApp VBScript Campaign Uses Fake Documents to Install ManageEngine RMM Tool

ID: c2ac10a9-2736-5488-8154-02a177969453

STIX ID: report--c2ac10a9-2736-5488-8154-02a177969453

Feed Name: The Hacker News

Threat Score
72/100

Date Published: 2026-06-23

Date Updated: 2026-06-23

Author: [email protected] (The Hacker News)

...
...

Kaspersky observed an active global campaign delivering obfuscated VBScript files via WhatsApp Desktop and Web that trick recipients into executing scripts which fetch additional payloads and ultimately install ManageEngine RMM Central, enabling remote access; the campaign targets multiple countries (notably Malaysia) and shows infrastructure overlap (202.61.160.201) with previously observed Gh0st RAT/ValleyRAT activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.