Threats · 167 days ago
Microsoft Defender observed a late‑Feb 2026 campaign delivering malicious VBS via WhatsApp messages. The VBS creates hidden folders under C:\ProgramData and drops renamed legitimate Windows utilities (curl.exe as netapi.dll; bitsadmin.exe as sc.exe). The dropped binaries retain original PE metadata fields such as OriginalFileName that still list their true filenames. The scripts use the renamed binaries to fetch follow‑on stages from trusted cloud hosts including AWS S3, Tencent Cloud, and Backblaze B2. The final stage installs malicious MSI packages to maintain persistent remote access. The campaign also attempts UAC elevation and modifies registry entries to persist.
2 sources covering this story
Microsoft Warns of WhatsApp-Delivered VBS Malware Hijacking Windows via UAC Bypass
WhatsApp VBS campaign began February 2026, abusing AWS and UAC bypass to gain persistent remote access.
WhatsApp malware campaign delivers VBScript and MSI backdoors | Microsoft Security Blog
A malware campaign uses WhatsApp messages to deliver VBS scripts that initiate a multi-stage infection chain.
Part of the PlainSec briefing for 2026-04-02