thehackernews.com 4/1/2026, 1:52:51 PM · via preferred

Microsoft Warns of WhatsApp-Delivered VBS Malware Hijacking Windows via UAC Bypass

WhatsApp on Windows users targeted in new campaign, warns Microsoft

Microsoft researchers found a campaign that abuses WhatsApp attachments to sneak a script onto Windows machines, which will lead to the attacker gaining remote control, according to Microsoft. The attack chain starts with a WhatsApp attachment that looks harmless but is actually a .vbs file that Windows can execute; when run, it copies built‑in Windows…

First seen 2026-04-01T13:49:32.240Z · Last seen 2026-04-01T15:25:03.090Z

CyberSIXT Evidence Panel
Primary Source microsoft.com

MICROSOFT has highlighted a new WhatsApp-delivered malware campaign that uses Visual Basic Script files to hijack Windows via a UAC bypass and establish persistence for remote access. The activity began in late February 2026 and distributes malicious VBS files through WhatsApp messages, initiating a multi-stage infection chain.

It involves renaming legitimate Windows utilities—curl[.]exe as netapi[.]dll and bitsadmin[.]exe as sc[.]exe—and dropping payloads from trusted cloud services such as AWS, Tencent Cloud, and Backblaze B2, before installing malicious MSI packages to maintain control. Once footholds are gained, the attackers aim to persist and escalate privileges, with the malware tampering with UAC settings and using registry modifications under HKLM\\Software\\Microsoft\\Win to survive reboots.

The campaign also references the use of legitimate tools like AnyDesk to provide persistent remote access, and relies on social engineering and living-off-the-land techniques, according to Microsoft Defender Security Research Team. This combination of tactics, trusted cloud hosting, and unsigned MSI installers underscores the need for heightened vigilance against WhatsApp-delivered threats.

View Primary Source Via thehackernews.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline