An active malware campaign is targeting WhatsApp users across multiple countries by sending obfuscated VBScript files disguised as business and financial documents from compromised contacts. When executed on Windows, the scripts disable UAC protections via Registry modifications and silently install ManageEngine Endpoint Central, a legitimate RMM tool, configured to connect to attacker-controlled servers for remote access. The campaign has been observed in Brazil, India, Mexico, Singapore, the UK, and several other countries. Kaspersky researchers found possible links to Chinese-language infrastructure and overlaps with ValleyRAT and Gh0st RAT activity, though attribution remains uncertain. Users are advised to verify unexpected files through secondary channels and scan all downloads before execution.

3m read timeFrom bleepingcomputer.com
Post cover image
Table of contents
Attack chainRelated Articles:
298 Impressions