Microsoft reported a multi-stage malware campaign that used WhatsApp messages to trick targets into opening malicious Visual Basic Script (.vbs) files. The activity, observed from late February 2026, relied on social engineering and trusted cloud infrastructure including AWS S3, Tencent Cloud, and Backblaze B2 to host follow-on payloads. After execution, the malware created hidden folders under ProgramData, downloaded additional VBS components, and used renamed legitimate Windows utilities to blend into normal system activity.
The intrusion chain then attempted UAC bypass, registry changes for persistence, and deployment of unsigned MSI installers including Setup.msi, WinRAR.msi, LinkPoint.msi, and AnyDesk.msi, which provided remote access and backdoor capability on compromised systems. Microsoft said the attackers abused living-off-the-land techniques such as renaming curl.exe and bitsadmin.exe while leaving original PE metadata intact, giving defenders a detection opportunity; the company also linked the activity to command-and-control domains neescil.top and velthora.top and published indicators, file hashes, and hunting guidance for defenders.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
The UK National Cyber Security Centre issued an advisory warning that state-backed actors, including Russia-linked operators, are increasingly targeting high-risk individuals through WhatsApp and Signal using impersonation, phishing links, malicious QR codes, account-linking abuse, and theft of login or recovery codes. The advisory referenced prior activity associated with APT31 and Star Blizzard and recommended protections such as two-step verification, Signal Registration Lock, passkeys, and device security updates.
On March 31, 2026, Microsoft disclosed the campaign publicly and released indicators, file hashes, command-and-control domains including neescil.top and velthora.top, and hunting guidance highlighting retained PE metadata in renamed binaries as a detection opportunity.
After victims executed the VBS files, the malware created hidden ProgramData folders, used renamed legitimate Windows utilities, fetched additional payloads from cloud services including AWS S3, Tencent Cloud, and Backblaze B2, attempted UAC bypass and registry-based persistence, and installed unsigned MSI packages such as Setup.msi, WinRAR.msi, LinkPoint.msi, and AnyDesk.msi.
Microsoft Defender Experts observed a malware campaign beginning in late February 2026 in which attackers used WhatsApp messages and social engineering to send malicious Visual Basic Script files to victims.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
blog.knowbe4.com
Open sourceitpro.com
Open sourcehackread.com
Open sourcecybersecuritynews.com
Open sourcescworld.com
Open sourcetechrepublic.com
Open sourcemicrosoft.com
Open sourcego.theregister.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.