WhatsApp VBS Drops Renamed Windows Tools, MSI Backdoors

Microsoft Defender observed a late‑Feb 2026 campaign delivering malicious VBS via WhatsApp messages. The VBS creates hidden folders under C:\ProgramData and drops renamed legitimate Windows utilities (curl.exe as netapi.dll; bitsadmin.exe as sc.exe). The dropped binaries retain original PE metadata fields such as OriginalFileName that still list their true filenames. The scripts use the renamed binaries to fetch follow‑on stages from trusted cloud hosts including AWS S3, Tencent Cloud, and Backblaze B2. The final stage installs malicious MSI packages to maintain persistent remote access. The campaign also attempts UAC elevation and modifies registry entries to persist.

Part of the PlainSec briefing for 2026-04-02

Sources