Microsoft is drawing attention to a recent campaign that spreads dangerous Visual Basic Script (VBS) files via WhatsApp messaging.
These scripts are used in the activity, which started in late February 2026, to start a multi-stage infection chain that establishes persistence and permits remote access. The lures used by threat actors to fool users into running the scripts are presently unknown.
According to the Microsoft Defender Security Research Team, the campaign uses a mix of living-off-the-land and social engineering strategies. It installs malicious Microsoft Installer (MSI) packages to keep control of the system, retrieves payloads from reliable cloud providers like AWS, Tencent Cloud, and Backblaze B2, and leverages renamed Windows utilities to blend in with regular system activities.
Threat actors can blend in with regular network activity by using trusted platforms and genuine tools, which increases the likelihood that their attacks will be successful read more about Microsoft Warns of WhatsApp-Delivered VBS Malware Hijacking Windows via UAC Bypass.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
