1 link tagged with all of: phishing + remote-access + vbscript + manageengine + whatsapp
Links
Attackers hijack WhatsApp accounts to send obfuscated VBScript files named as business or financial documents. When opened, the script disables UAC, downloads ManageEngine Endpoint Central, and connects the PC to attacker-controlled servers for remote administration. The campaign hits users in over a dozen countries, though how WhatsApp accounts are first compromised remains unclear.
- Attackers are hijacking WhatsApp accounts to send malicious VBScript files disguised as invoices or financial reports, hitting users across 11+ countries.
- Opening the file disables UAC, then silently installs the legitimate ManageEngine Endpoint Central tool to give attackers full remote control of the PC.
- Code artifacts point to Chinese-language origins and overlap with ValleyRAT/Gh0st RAT infrastructure, though no group has been formally attributed.
- It's still unknown how the attackers are initially compromising victims' WhatsApp accounts.
whatsapp
phishing
vbscript
manageengine
remote-access