VBScript security alert disguised as WhatsApp invoices delivers persistent remote access to Windows

Author: Published 4 min de lectura 224 reading

The images in this article were generated with artificial intelligence. How we publish

A malicious campaign spread by WhatsApp is using camouflaged VBScript files as invoices and financial documents to deliver persistent remote access to Windows equipment: when you open the file, the VBS download more scripts, disable UAC protections by changing the Register and hides the installation of a legitimate remote management tool, ManageEngine Endpoint Central, which is configured to connect to servers controlled by the attackers.

Kaspersky researchers have documented that the messages come from previously committed contact accounts, and that the file names are located in several languages to increase the trap. The technical report of Kaspersky for indicators and samples is available at: https: / / sequrelist.com / Whatsapp-vbs-rmm-campaign / 120290 /. This technique combines social engineering with the abuse of legitimate software, a classic tactic to evade detection: by using a product known to administrators, attackers reduce alarms and get real remote control over the victim machine.

VBScript security alert disguised as WhatsApp invoices delivers persistent remote access to Windows
Image generated with IA.

A critical point from which we must all learn is that the means of delivery matters: when the file is opened in WhatsApp Desktop can be run directly using Windows Script Host (wscript.exe), while in WhatsApp Web the user must first download it. This difference increases the risk for users who keep the desktop application open and run files without checking them.

The implications are serious for personal users and organizations. For a company, the unauthorized installation of a remote management agent can allow data exfiltration, lateral movement and future deployment of more harmful loads. For domestic users, it represents the loss of control of devices and exposure of sensitive credentials and documents.

Recommended immediate action: do not open .vbs files or run scripts received by messaging; verify any unexpected shipment with the person sending it on a different channel (called or SMS); and scan any downloaded file with an updated antivirus before running it. To protect workstations, consider disabling Windows Script Host by means of the registration key (e.g. by adjusting HKLM\\ Software\\ Microsoft\\ Windows Script Host\\ Settings\\ Enable to 0) or by group policies, and blocking the execution of wscript.exe if not required.

If you suspect that a team was engaged, isolate it from the network, ask your IT team to review services and processes for remote management agents (e.g. ManageEngine / Endpoint Central), review the Register for Policy Changes of UAC and review scheduled tasks and outgoing connections to unknown servers. Do a complete scanning with detection / EDR tools and restore local and administrator credentials if the intrusion is confirmed.

At the organizational level, more stringent policies on remote management software should be applied: to restrict the installation and management of tools such as Endpoint Central to authenticated servers and accounts, require strong authentication, review certificates and whitelists of management servers, and monitor network telemetry for connections to unapproved destinations. Official product information is available at https: / / www.manageengine.com / products / endpoint-central /.

VBScript security alert disguised as WhatsApp invoices delivers persistent remote access to Windows
Image generated with IA.

To reduce the risk that legitimate WhatsApp accounts will be used as attack vectors, users should close remote sessions, activate verification in two steps in WhatsApp and review linked devices from the application configuration. WhatsApp publishes safety recommendations in https: / / www.Whatsapp.com / security.

Finally, it is important for security teams to share indicators and correlate events with suppliers and response communities: this campaign is already global in scope and has affected multiple countries, so collaboration can accelerate detection and mitigation. Keep copies of evidence, record associated times and domains / PIs and, if appropriate, raise the incident to CERT / CISO for coordinated actions.

Practical summary: do not open .vbs received by messaging, check other ways for unexpected shipments, update and use antivirus / EDR, disable WSH if not necessary and immediately review any new installation of remote administration agents. Prevention and verification are the most effective barriers to such campaigns.

Coverage

Related

More news on the same subject.