An unknown actor distributes malicious VBS scripts via WhatsApp

June 22, 2026, 8:07 p.m.

Description

An active malware campaign has been discovered distributing malicious VBScript files through WhatsApp direct messages since June 2026. The operation affects users across multiple countries, with Malaysia experiencing the highest concentration of victims. Attackers compromise WhatsApp accounts and send weaponized VBS files disguised as business and financial documents to contacts. The multi-stage infection chain ultimately deploys legitimate ManageEngine Endpoint Central RMM software, providing persistent remote access to compromised systems. The scripts employ heavy obfuscation, Chinese-language comments, and modify Windows UAC settings. Infrastructure overlaps with ValleyRAT and Gh0st RAT operations suggest possible Chinese-speaking operators, though attribution remains uncertain. The campaign primarily targets individual users through opportunistic rather than focused methods, exploiting social engineering techniques with localized filenames in multiple languages.

Date

  • Created: June 22, 2026, 11:01 a.m.
  • Published: June 22, 2026, 11:01 a.m.
  • Modified: June 22, 2026, 8:07 p.m.

Indicators

  • 50c74b468c217776b8890b841baefec8b196b14083a7873a9201c838a8e4c90a
  • 01f1eb07125db5de0c2362afc777aa015f136feabd769628f01d01ac6472646c
  • 452259dc297f56cf22c7932e8fbcefe821ef9c3127134074fae585f89355d397
  • 202.61.160.137
  • 202.61.160.160
  • 202.61.160.208
  • 202.61.160.202
  • 38.55.151.63
  • 202.61.160.201

Additional Informations

  • baoxis.cc
  • temu.baskwms.top
  • invoice.msopsa.top
  • Taiwan
  • Brazil
  • India
  • British Indian Ocean Territory
  • Australia
  • United Kingdom of Great Britain and Northern Ireland
  • Malaysia
  • Singapore
  • Spain
  • Mexico
  • Russian Federation