Researchers reported an active campaign in which compromised WhatsApp accounts sent malicious .vbs attachments to targets in multiple countries, with most observed infections in Malaysia. The lures impersonated business, banking, tax, and debt-related documents and primarily targeted users of WhatsApp Desktop and WhatsApp Web. When opened, the VBScript launched through Windows Script Host, created hidden working directories, and fetched additional payloads from attacker-controlled infrastructure while using obfuscation and renamed native tools such as curl.exe and bitsadmin.exe to reduce detection.
A second-stage script attempted to weaken Windows User Account Control by changing ConsentPromptBehaviorAdmin, then downloaded a ZIP archive containing a preconfigured ManageEngine Endpoint Central deployment package. The final stage silently installed the legitimate ManageEngine Endpoint Central agent via msiexec.exe, giving the attacker remote administration access to the compromised system. Attribution remains unconfirmed, but researchers noted simplified Chinese comments in the scripts and infrastructure overlap with IP addresses previously associated with ValleyRAT and Gh0st RAT activity, indicating with low confidence that a Chinese-speaking operator may be behind the campaign.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Erik Hjelmvik analyzed the June 2026 WhatsApp-delivered VBScript campaign and identified a related sample that downloaded a dropper from Backblaze B2 and installed the Ping32 remote monitoring and management tool instead of ManageEngine Endpoint Central. By pivoting on the Ping32 C2 server, he also found infrastructure overlap with DonutLoader and ValleyRAT using UDP port 10086 and the Gh0stKCP protocol, strengthening but not confirming the ValleyRAT connection.
Kaspersky disclosed additional details on the WhatsApp malware campaign, saying hijacked accounts sent fake debt-related VBScript attachments that used multi-stage obfuscated scripts, attempted to weaken Windows UAC via registry changes, and silently installed a pre-configured ManageEngine Endpoint Central agent. The researchers also reported infrastructure overlap with activity linked to ValleyRAT and Gh0st RAT, but said attribution remained unconfirmed and only low-confidence indicators suggested a Chinese-speaking operator.
Researchers observed an active malware campaign in June 2026 in which compromised WhatsApp accounts sent malicious VBScript attachments to victims in multiple countries, with Malaysia accounting for most observed infections. The infection chain ultimately installed the legitimate ManageEngine Endpoint Central agent to provide the attacker with remote administration access.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
9 references tracked. Mallory keeps watching after this page renders.
netresec.com
Open sourcethehackernews.com
Open sourcecommunity.gurucul.com
Open sourcecysecurity.news
Open sourcesecurityaffairs.com
Open sourcecybersecuritynews.com
Open sourcemalware.news
Open sourcebleepingcomputer.com
Open sourcesecurelist.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.