malware
A VBScript campaign distributed through WhatsApp deploying RMM software
High
Summary
A WhatsApp-distributed malware campaign, active as of June 2026, leverages deceptive VBScript files disguised as financial documents to trick users into executing malicious code. This code ultimately installs legitimate Remote Monitoring and Management (RMM) software, gaining remote access to infected systems. The campaign targets users of WhatsApp Desktop and Web across multiple countries, utilizing social engineering tactics and mimicking Windows Update components.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
