Vjw0rm is a commodity JavaScript remote access trojan (RAT) first seen around 2016 and originally associated with an author known as "v-j." It uses Windows Script Host components including WScript.Shell, ActiveXObject, and MSScriptControl for execution and dynamic scripting. Documented capabilities include command execution, file operations, registry operations, environment reconnaissance, WMI-based security product enumeration, and self-propagation to USB or network locations. Reporting cited in the content also notes that malware used in TA2541 campaigns, including vjw0rm, supports information gathering and remote control of infected machines.
The malware has been observed in phishing-driven intrusion chains associated with TA2541, a financially motivated cybercriminal actor active since at least 2017. TA2541 has targeted aviation, aerospace, transportation, manufacturing, and defense organizations, typically using aviation-, transportation-, and travel-themed lures delivered via high-volume email campaigns. In these campaigns, vjw0rm has been delivered through chains involving obfuscated VBS files, PowerShell, cloud-hosted payloads, and persistence via scheduled tasks and Windows Registry Run keys. Proofpoint specifically observed recent vjw0rm campaigns leveraging task creation and registry persistence.
A separate 2026 campaign described in the content used a WinRAR self-extracting archive disguised as a software keygen to deploy Vjw0rm through a four-layer dropper chain. The outer archive silently executed a decoy KeyGen.exe and a nested Patch.exe SFX archive. Patch.exe dropped setup.exe, a compiled AutoHotkey orchestrator, along with approximately 200 legitimate Windows troubleshooting pack files used as camouflage. The orchestrator staged payloads under C:\ProgramData\Adobe\AIR\Logs\gp\PerfLogs\Google\start\ and C:\Users\Public\Settings\A\News, then launched win.ps1, Script.js, Patch.js, and a renamed WindowsUpdater.js in parallel. win.ps1 and Script.js both retrieved content from hxxps://upaste[.]me/r/8dc960578b490d703, which functioned as a dead-drop resolver. Script.js established persistence by copying itself to %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\Script.js, while Patch.js created scheduled tasks and used Unicode fullwidth character obfuscation. The final RAT core was embedded locally as PCWDiagnostic.xml (SHA256 33629caa9918c81a5e1ce58c1682e7465ac6f4bccd8d9c13d429249920c6d557), renamed to WindowsUpdater.js, and executed as Vjw0rm. Additional artifacts from this campaign include outer SFX SHA256 64a92d23f6efcc17cdd3016a52e0503a13350f037785220a08b74b46333a3eee, nested Patch.exe SHA256 4a341185e5e0983feca8a39b65b92a6d69b72d2093aa1a1b134b39d63a1c9a96, setup.exe SHA256 0419d91f867968fce085b3a1bbe3c3dc96e1b83e8e8c27d4a5d4e64be1389dcc, and GUID 34892937-8948-47dc-9c73-e8f5c918f49a in Patch.js. Turkish-language artifacts in the SFX comment suggested a likely Turkish-speaking commodity cybercrime operator.
The content also notes that Vjw0rm has appeared in broader commodity malware delivery ecosystems beyond TA2541, including campaigns documented by Proofpoint and Positive Technologies and activity associated with the RevengeHotels/TA558 cluster, where it was one of several RATs delivered in campaigns targeting hospitality and travel-related victims.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In recent campaigns, vjw0rm and STRRAT also leveraged task creation and adding entries to the registry.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
TA2541 uses themes related to aviation, transportation, and travel. When Proofpoint first started tracking this actor, the group sent macro-laden Microsoft Word attachments that downloaded the RAT payload. The group pivoted, and now they more frequently send messages with links to cloud services such as Google Drive hosting the payload.
TA2541 has also established persistence by creating scheduled tasks... In recent campaigns, vjw0rm and STRRAT also leveraged task creation... Scheduled Task: schtasks.exe /Create /TN "Updates\BQVIiVtepLtz" /XML C:\Users\[User]\AppData\Local\Temp\tmp7CF8.tmp
If executed, PowerShell pulls an executable from a text file hosted on various platforms such as Pastetext, Sharetext, and GitHub. The threat actor executes PowerShell into various Windows processes and queries Windows Management Instrumentation (WMI) for security products such as antivirus and firewall software, and attempts to disable built-in security protections.
Execution Command and Scripting Interpreter: Visual Basic T1059.005 VBScript payload constructed in Script.js
TA2541 has also established persistence by creating scheduled tasks... In recent campaigns, vjw0rm and STRRAT also leveraged task creation... Scheduled Task: schtasks.exe /Create /TN "Updates\BQVIiVtepLtz" /XML C:\Users\[User]\AppData\Local\Temp\tmp7CF8.tmp
Obfuscation Basic JS obfuscation, string splitting Multi-technology: UTF-16LE encoding, Base64, XOR, ROT substitution, Unicode fullwidth characters, MSScriptControl dynamic execution
Defense Evasion Masquerading: Rename System Utilities T1036.003 Legitimate directory names (Adobe, PerfLogs, Google)
Defense Evasion Masquerading: Match Legitimate Name T1036.005 PCWDiagnostic.xml, WindowsUpdater directory, Adobe/Google paths
Command and Control Application Layer Protocol: Web Protocols T1071.001 HTTPS download from upaste[.]me
15 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Commodity JavaScript remote access trojan/worm that runs via Windows Script Host. In this campaign it is deployed through a multi-layer dropper chain and provides command execution, COM automation, dynamic scripting via MSScriptControl, persistence, file and registry operations, WMI-based security product enumeration, environment reconnaissance, and self-propagation via USB/network spread.
Vjw0rm is a remote access trojan used for remote control and data theft, deployed in phishing campaigns against the hospitality sector.
Commodity malware used by TA2541 that supports remote access/information gathering and persistence through scheduled tasks and registry run keys.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.