Threats & Adversaries
Microsoft Defender observed a late‑Feb 2026 campaign delivering malicious VBS via WhatsApp messages. The VBS creates hidden folders under C:\ProgramData and drops renamed legitimate Windows utilities (curl.exe as netapi.dll; bitsadmin.exe as sc.exe). The dropped binaries retain original PE metadata fields such as OriginalFileName that still list their true filenames. The scripts use the renamed binaries to fetch follow‑on stages from trusted cloud hosts including AWS S3, Tencent Cloud, and Backblaze B2. The final stage installs malicious MSI packages to maintain persistent remote access. The campaign also attempts UAC elevation and modifies registry entries to persist.
2 sources · Apr 1
The Hacker News
Microsoft Warns of WhatsApp-Delivered VBS Malware Hijacking Windows via UAC Bypass
WhatsApp VBS campaign began February 2026, abusing AWS and UAC bypass to gain persistent remote access.
originalMicrosoft Security Blog
WhatsApp malware campaign delivers VBScript and MSI backdoors | Microsoft Security Blog
A malware campaign uses WhatsApp messages to deliver VBS scripts that initiate a multi-stage infection chain.
originalPart of the PlainSec briefing for 2026-04-01
Every edition of this story: WhatsApp VBS Drops Renamed Windows Tools, MSI Backdoors