Microsoft Warns of WhatsApp-Delivered VBS Malware Hijacking Windows via UAC Bypass
Microsoft is drawing attention to a recent campaign that spreads dangerous Visual Basic Script (VBS) files via WhatsApp messaging.
These scripts are used in the activity, which started in late February 2026, to start a multi-stage infection chain that establishes persistence and permits remote access. The lures used by threat actors to fool users into running the scripts are presently unknown.
According to the Microsoft Defender Security Research Team, the campaign uses a mix of living-off-the-land and social engineering strategies. It installs malicious Microsoft Installer (MSI) packages to keep control of the system, retrieves payloads from reliable cloud providers like AWS, Tencent Cloud, and Backblaze B2, and leverages renamed Windows utilities to blend in with regular system ac...

