A VBScript campaign distributed through WhatsApp deploying RMM software
News Source : Securelist.com
News Summary
- In June 2026, we observed a malware campaign distributing malicious VBScript files through direct messages in WhatsApp.
- The campaign affected users across multiple countries and territories, including Malaysia, Brazil, India, Mexico, Singapore, UK, Spain, Taiwan, Australia, Russia and Vietnam.
- At the time of writing this article, the campaign is still active.
- Analysis shows that the campaign primarily targets users of WhatsApp Desktop and WhatsApp Web.
- The threat actor uses deceptive file names masquerading as business and financial documents to persuade recipients to download and execute the attachment.
In June 2026, we observed a malware campaign distributing malicious VBScript files through direct messages in WhatsApp.
Never miss a story from us, subscribe to our newsletter