HomeSecurity"WhatsApp malware" campaign uses malicious VBS files

“WhatsApp malware” campaign uses malicious VBS files

Microsoft is warning WhatsApp users about a new malware campaign that tricks them into executing malicious Visual Basic Script (VBS) files , thus allowing persistent access and remote control .

WhatsApp malware VBS

Microsoft Defender experts reported that attackers have been distributing malicious VBS files via WhatsApp since at least late February, relying on social engineering .

Once executed, the scripts trigger a delayed execution of malware, starting a multi-layered infection flow. This is designed to blend into normal system activity while in the background downloading additional payloads for remote control.

See also: FBI: Russian hackers target Signal and WhatsApp accounts

“The campaign relies on a combination of social engineering and living-off-the-land (LOTL) techniques,” Microsoft researchers wrote in the report. “By combining trusted platforms with legitimate tools, the attacker reduces visibility and increases the likelihood of successful execution.”

The campaign eventually installs malicious Microsoft Installer (MSI) packages to maintain control over infected devices.

How does the attack against WhatsApp users work?

The attack begins with a WhatsApp message that carries a VBS file. Once executed, the script creates hidden directories on the system and begins preparing the next steps of the breach.

"WhatsApp malware" campaign uses malicious VBS files

However, instead of directly dropping custom malware, the campaign switches to living-off-the-land. The VBS payload deploys renamed versions of legitimate Windows, such as curl.exe and bitsadmin.exe, disguised under deceptive filenames to avoid casual inspection. These binaries retain their original metadata, but their altered names allow them to integrate into the environment while performing malicious tasks such as downloading additional payloads.

See also: New ways to protect against fraud on Facebook, WhatsApp and Messenger

“Microsoft Defender and other security solutions can leverage this metadata difference as a detection signal, highlighting cases where a file name does not match the embedded OriginalFileName,” the report added.

The researchers noted that even payload retrieval is done from legitimate hosting sources. The attackers host components on well-known cloud platforms, including AWS, Tencent Cloud, and Blackblaze B2. The use of these trusted tools, reliable infrastructure, and staged execution makes the attack relatively invisible.

Backdoor delivery

The final stages of the campaign lead to persistent access, using Microsoft Installer (MSI) packages as a delivery mechanism for backdoors. MSI files are an effective option as they are typically not considered inherently suspicious and can perform custom actions upon installation. In this campaign, they are used to deploy malware that maintains access, escalates privileges, and allows remote control of infected systems.

By the time the MSI component is installed, attackers have already established an access point using scripts and system tools, making the backdoor just one layer in a broader persistence strategy found by Microsoft.

See also: Netherlands: Russian hackers breach Signal, WhatsApp accounts of officials

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Graphican backdoor

The previous stages ensure that the environment is prepared, while the installer formalizes long-term access. Microsoft also noted that the campaign incorporates privilege escalation to enhance persistence, allowing the malware to run with elevated privileges and maintain access beyond the initial user-level breach.

Recommendations included monitoring script execution and installations, monitoring for misuse of legitimate tools , and monitoring suspicious activity related to files delivered via platforms like WhatsApp.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS