securityonline.info 6/26/2026, 9:40:35 AM · external

WhatsApp malware spreads VBScript with hidden RMM payloads

WhatsApp malware spreads VBScript with hidden RMM payloads
Developing story malware 2 articles tracked
WhatsApp VBScript malware campaign distributes RMM payloads
CyberSIXT Evidence Panel Source marked as original reporting

A new WhatsApp malware campaign has been identified, involving a threat actor that hijacks accounts to send malicious VBScript files to users, primarily in Malaysia. The scripts are disguised as financial documents and use localization to trick victims. Once executed, the malware downloads secondary payloads, bypasses Windows security measures, and installs legitimate Remote Monitoring and Management (RMM) software, allowing attackers to control infected systems silently.

The campaign has a broad impact, targeting individual users across various nations and utilizing obfuscation techniques to conceal its operations. Users are advised to avoid opening unexpected script attachments and ensure their security software is up to date.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline