WhatsApp Malware Campaign Delivers VBS Files, Enabling Remote Access on Windows Systems

A sophisticated malware campaign is leveraging WhatsApp to distribute malicious Visual Basic Script (VBS) files, targeting Windows users across multiple countries. Microsoft and cybersecurity firms have issued warnings regarding the threat, which enables attackers to gain remote access and system control over compromised machines. The attack began in late February 2026 and remains actively in operation.

The campaign’s primary method of infection involves sending WhatsApp messages containing these malicious VBS files. Once executed, the script initiates a multi-stage infection chain. Attackers rename standard Windows utilities like ‘curl.exe’ (appearing as ‘netapi.dll’) and ‘bitsadmin.exe’ (displayed as ‘sc.exe’) to blend in with normal system activity, making detection more difficult. These renamed binaries retain their original PE metadata for further obfuscation.

A key element of this attack is the use of trusted cloud services like AWS S3, Tencent Cloud, and Backblaze B2 to retrieve secondary payloads. This tactic significantly reduces visibility as the malware leverages platforms considered legitimate and secure by many users.

The attackers also modify User Account Control (UAC) settings to bypass system defenses, allowing them to gain elevated privileges and further solidify their foothold on the infected system. Microsoft Defender Experts have observed that the malware creates hidden folders within the C:\ProgramData directory and drops these renamed Windows utilities.

Security researchers highlight the risk of this campaign for Windows users who may not be aware of the potential dangers lurking within seemingly harmless WhatsApp messages. While Malaysia has been particularly impacted, the threat extends globally. Users are urged to keep their systems updated with the latest security patches and exercise caution when opening attachments from unknown senders.

Microsoft advises exercising extra caution when interacting with unexpected WhatsApp messages, especially those containing file attachments. The campaign underscores the importance of vigilance and proactive security measures in protecting against social engineering attacks that exploit trusted communication channels.

Sources: