Back to Intel

Intel Node

A VBScript campaign distributed through WhatsApp deploying RMM software

lowapt2026-06-22T10:00:38+00:00source excerpt
aptmalwarewindows

Source excerpt · The upstream feed supplied only part of this article.Read the original source →

A Kaspersky researcher analyzes a global malicious campaign that distributes VBS scripts via WhatsApp delivering a UEMS RMM agent through a multi-stage infection chain.

In June 2026, we observed a malware campaign distributing malicious VBScript files through direct messages in WhatsApp. The campaign affected users across multiple countries and territories, including Malaysia, Brazil, India, Mexico, Singapore, UK, Spain, Taiwan, Australia, Russia and Vietnam, with the highest number of victims observed in Malaysia. At the time of writing this article, the campaign is still active. Analysis shows that the campaign primarily targets users of WhatsApp Desktop and WhatsApp Web.

The threat actor uses deceptive file names masquerading as business and financial documents to persuade recipients to download and execute the attachment. Once executed, the VBScript initiates a multi-stage infection chain that ultimately results in the installation of legitimate Remote Monitoring and Management (RMM) software, enabling remote access to the victim’s system.

Read Original Source