Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
remote-access-implantphishing-campaign-intelligenceloader-delivery-mechanismpersistence-method

WhatsApp Malware Campaign Used VBS Files and Unsigned MSI Backdoors

Updated 2mo agoFirst seen Mar 31, 20268 sources

Microsoft reported a multi-stage malware campaign that used WhatsApp messages to trick targets into opening malicious Visual Basic Script (.vbs) files. The activity, observed from late February 2026, relied on social engineering and trusted cloud infrastructure including AWS S3, Tencent Cloud, and Backblaze B2 to host follow-on payloads. After execution, the malware created hidden folders under ProgramData, downloaded additional VBS components, and used renamed legitimate Windows utilities to blend into normal system activity.

The intrusion chain then attempted UAC bypass, registry changes for persistence, and deployment of unsigned MSI installers including Setup.msi, WinRAR.msi, LinkPoint.msi, and AnyDesk.msi, which provided remote access and backdoor capability on compromised systems. Microsoft said the attackers abused living-off-the-land techniques such as renaming curl.exe and bitsadmin.exe while leaving original PE metadata intact, giving defenders a detection opportunity; the company also linked the activity to command-and-control domains neescil.top and velthora.top and published indicators, file hashes, and hunting guidance for defenders.

Share:
WhatsApp Malware Campaign Used VBS Files and Unsigned MSI Backdoors
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Apr 3, 20263mo ago

UK NCSC warns of state-backed targeting via WhatsApp and Signal

The UK National Cyber Security Centre issued an advisory warning that state-backed actors, including Russia-linked operators, are increasingly targeting high-risk individuals through WhatsApp and Signal using impersonation, phishing links, malicious QR codes, account-linking abuse, and theft of login or recovery codes. The advisory referenced prior activity associated with APT31 and Star Blizzard and recommended protections such as two-step verification, Signal Registration Lock, passkeys, and device security updates.

Microsoft and NCSC issue alerts over hacker campaigns targeting WhatsApp, Signal messaging apps | IT Pro
Mar 31, 20263mo ago

Microsoft publishes technical analysis and detection guidance

On March 31, 2026, Microsoft disclosed the campaign publicly and released indicators, file hashes, command-and-control domains including neescil.top and velthora.top, and hunting guidance highlighting retained PE metadata in renamed binaries as a detection opportunity.

Feb 28, 20264mo ago

Attackers deploy multi-stage MSI backdoor infection chain

After victims executed the VBS files, the malware created hidden ProgramData folders, used renamed legitimate Windows utilities, fetched additional payloads from cloud services including AWS S3, Tencent Cloud, and Backblaze B2, attempted UAC bypass and registry-based persistence, and installed unsigned MSI packages such as Setup.msi, WinRAR.msi, LinkPoint.msi, and AnyDesk.msi.

WhatsApp malware campaign begins delivering malicious VBS files

Microsoft Defender Experts observed a malware campaign beginning in late February 2026 in which attackers used WhatsApp messages and social engineering to send malicious Visual Basic Script files to victims.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

28 LINKEDOpen in app
Threat actors
2 linked
Affected products
10 linked
WhatsappWindowsAnydeskWinrarAmazon Web ServicesMicrosoft Defender For EndpointCopilot StudioSignalGoogle SearchMicrosoft 365 Copilot
Organizations
16 linked
TencentAmazon Web ServicesMicrosoft CorporationBackblazeMeta PlatformsWinRARAnyDesk Software GmbHKeeper SecurityLinkedinXPolygraf AIJamfSweet SecuritySignal MessengerGoogleTokenCore
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.