WhatsApp DM Campaign Distributes VBScript to Install Legitimate RMM Software
Block VBScript file downloads from WhatsApp and scan for installed RMM software to mitigate the campaign.
Block VBScript file downloads from WhatsApp and scan for installed RMM software.
Summary
Kaspersky researchers have identified a campaign that uses WhatsApp Desktop and Web messages to distribute malicious VBScript files, which in turn install legitimate Remote Monitoring and Management (RMM) software. The campaign targets users across Malaysia, Brazil, India, Mexico, Singapore, the United Kingdom, Spain, Taiwan, and Australia. The VBScript files masquerade as benign downloads, tricking users into executing them and installing RMM tools that grant attackers remote access.
The use of legitimate RMM software provides a stealthy foothold for attackers to maintain persistence. The campaign demonstrates the evolving threat of messaging platforms as vectors for malware distribution. Users and organizations should block VBScript downloads and monitor for unauthorized RMM installations.
Key changes
- WhatsApp Desktop/Web targeted by malicious VBScript files
- VBScript leads to installation of legitimate RMM software
- Campaign active across Malaysia, Brazil, India, Mexico, Singapore, UK, Spain, Taiwan, Australia
- Attackers use WhatsApp messages to distribute malware
- RMM software installed under guise of legitimate tool
- Users can be compromised via simple file download