WhatsApp VBScript Campaign Uses Fake Documents to Install ManageEngine RMM Tool
Malicious Visual Basic Script (VBScript) files that cause the installation of authentic Remote Monitoring and Management (RMM) software are being distributed through direct messages received via WhatsApp.
According to Kaspersky research, users of WhatsApp Desktop and WhatsApp Web in Malaysia, Brazil, India, Mexico, Singapore, the United Kingdom, Spain, Taiwan, Australia, Russia, and Vietnam are the focus of the current effort. Malaysia has been claimed to have the highest concentration of victims.
According to security researcher Fareed Radzi, the threat actor tricked recipients into downloading and running the attachment by using false file names that looked like financial and business papers. After the VBScript is run, it starts a multi-phase infection chain that eventually instal...

