Close Menu

    Subscribe to Updates

    Get the latest creative news from infofortech

    What's Hot

    Best Prime Day Tech Deals (2026): Phones, Watches, and More

    June 23, 2026

    WhatsApp VBScript Campaign Uses Fake Documents to Install ManageEngine RMM Tool

    June 23, 2026

    The Antichrist and Trump: An old evangelical Christian idea is politics now.

    June 23, 2026
    Facebook X (Twitter) Instagram
    InfoForTech
    • Home
    • Latest in Tech
    • Artificial Intelligence
    • Cybersecurity
    • Innovation
    Facebook X (Twitter) Instagram
    InfoForTech
    Home»Cybersecurity»WhatsApp VBScript Campaign Uses Fake Documents to Install ManageEngine RMM Tool
    Cybersecurity

    WhatsApp VBScript Campaign Uses Fake Documents to Install ManageEngine RMM Tool

    InfoForTechBy InfoForTechJune 23, 2026No Comments3 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    WhatsApp VBScript Campaign Uses Fake Documents to Install ManageEngine RMM Tool
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email


    Ravie LakshmananJun 23, 2026Malware / Social Engineering

    Direct messages sent via WhatsApp are being used to distribute malicious Visual Basic Script (VBScript) files that lead to the installation of legitimate Remote Monitoring and Management (RMM) software.

    Per findings from Kaspersky, the active campaign is targeting users of WhatsApp Desktop and WhatsApp Web across Malaysia, Brazil, India, Mexico, Singapore, the U.K., Spain, Taiwan, Australia, Russia, and Vietnam. The highest concentration of victims has been reported in Malaysia.

    “The threat actor uses deceptive file names masquerading as business and financial documents to persuade recipients to download and execute the attachment,” security researcher Fareed Radzi said. “Once executed, the VBScript initiates a multi-stage infection chain that ultimately results in the installation of legitimate Remote Monitoring and Management (RMM) software, enabling remote access to the victim’s system.”

    It’s suspected that the threat actor behind the operation managed to obtain surreptitious access to several WhatsApp accounts and then used them as a distribution vector for the VBScript files across their contacts. That said, exactly how these accounts are compromised is unclear.

    The heavily obfuscated VBScript files are dressed up as seemingly harmless business and financial documents, using names like “Financial Reports.vbs” or “Account Statement.vbs.” Some of the files are also named in other languages, such as Portuguese, French, German, and Malay, reflective of the global nature of the campaign.

    “In addition, the VBScript samples contain extensive comments and metadata intended to mimic legitimate Microsoft Windows Update components,” Kaspersky explained. “Many of these comments are written in Chinese and include references to Windows Update modules, certificate validation, system integrity checks, and deployment-related functionality.”

    The VBScript file is launched using “WScript.exe,” which then fetches and runs additional VBScript components required for the next stages of the attack. It’s worth noting that the infection chain behaves a little differently based on whether a victim is using WhatsApp Web or the WhatsApp Desktop application. 

    In the case of the former, the attack relies on the user downloading the file to their system and then opening it from the downloaded folder or via the browser’s download history, assuming it to be a legitimate document. In WhatsApp Desktop, the malware is executed directly within the application, with the process tree revealing that “WhatsApp.Root.exe,” the background process associated with the client application, is responsible for spawning “WScript.exe.”

    The primary objective of the VBScript is to download two secondary VBScript payloads from a remote server, one of which attempts to tamper with Windows User Account Control (UAC) behavior, while the other downloads and executes a ZIP file containing the installation package for ManageEngine RMM Central.

    The activity remains unattributed, however, the Russian cybersecurity company said it found infrastructure overlaps (“202.61.160[.]201”) with prior activity linked to Gh0st RAT and ValleyRAT.

    “Users should be cautious when receiving unexpected attachments through WhatsApp, even when they appear to originate from known contacts,” Kaspersky said. “Script and executable file types such as VBS, VBE, EXE, BAT, CMD, JS, and PS1 should not be opened unless their legitimacy has been independently verified.”

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    InfoForTech
    • Website

    Related Posts

    29-Year-Old Squid Proxy Bug ‘Squidbleed’ Can Leak Cleartext HTTP Requests

    June 22, 2026

    The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes

    June 22, 2026

    Unpatchable ‘usbliter8’ Exploit Breaks Apple A12 and A13 SecureROM Boot Chain

    June 21, 2026

    Apple Patches Beats Studio Buds Wiretap Flaw

    June 21, 2026

    Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys

    June 20, 2026

    124M Passwords Exposed as Infostealer Malware Hits Millions of Devices

    June 20, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks

    March 20, 202638 Views

    Microsoft is bringing an AI helper to Xbox consoles

    March 14, 202616 Views

    This is the tech that makes Volvo’s latest EV a major step forward

    January 24, 202616 Views

    Why Security Validation Is Becoming Agentic

    March 16, 202615 Views
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Advertisement
    About Us
    About Us

    Our mission is to deliver clear, reliable, and up-to-date information about the technologies shaping the modern world. We focus on breaking down complex topics into easy-to-understand insights for professionals, enthusiasts, and everyday readers alike.

    We're accepting new partnerships right now.

    Facebook X (Twitter) YouTube
    Most Popular

    DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks

    March 20, 202638 Views

    Microsoft is bringing an AI helper to Xbox consoles

    March 14, 202616 Views

    This is the tech that makes Volvo’s latest EV a major step forward

    January 24, 202616 Views
    Categories
    • Artificial Intelligence
    • Cybersecurity
    • Innovation
    • Latest in Tech
    © 2026 All Rights Reserved InfoForTech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.