PULSE NAME
WhatsApp malware campaign delivers VBScript and MSI backdoors
WHITE AlienVault 2026-03-31 Modified: 2026-03-31
22
IOCs
MEDIUM VOLUME
A sophisticated malware campaign targeting WhatsApp users has been observed since February 2026. The attack chain begins with malicious Visual Basic Script files sent via WhatsApp messages, which, when executed, initiate a multi-stage infection process. The malware uses renamed Windows utilities, retrieves payloads from trusted cloud services, and installs malicious MSI packages. The campaign employs social engineering, stealth techniques, and cloud-based payload hosting to establish persistence and escalate privileges on victim systems. The attackers utilize legitimate tools and trusted platforms to reduce visibility and increase the likelihood of successful execution. The final stage involves the delivery of unsigned MSI installers that enable remote access to compromised systems.
Indicators of Compromise (22)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 1304f43c5fddcf664ba0f068a5a7bc18 2026-03-31
FileHash-MD5 2d9ef700fb9ce1550ca73f50428fef87 2026-03-31
FileHash-MD5 3466746d84501cb07a9833057e835565 2026-03-31
FileHash-SHA1 1fb0cb93de16671e3d4123438147549b47d10fdc 2026-03-31
FileHash-SHA1 68e6071ec9210bce297d30c209ddf4026fd5a4f1 2026-03-31
FileHash-SHA1 c8e5795f32b3c9d94b8aa3811fe3f61725fa5869 2026-03-31
FileHash-SHA256 07c6234b02017ffee2a1740c66e84d1ad2d37f214825169c30c50a0bc2904321 2026-03-31
FileHash-SHA256 15a730d22f25f87a081bb2723393e6695d2aab38c0eafe9d7058e36f4f589220 2026-03-31
FileHash-SHA256 1735fcb8989c99bc8b9741f2a7dbf9ab42b7855e8e9a395c21f11450c35ebb0c 2026-03-31
FileHash-SHA256 1f726b67223067f6cdc9ff5f14f32c3853e7472cebe954a53134a7bae91329f0 2026-03-31
FileHash-SHA256 22b82421363026940a565d4ffbb7ce4e7798cdc5f53dda9d3229eb8ef3e0289a 2026-03-31
FileHash-SHA256 57bf1c25b7a12d28174e871574d78b4724d575952c48ca094573c19bdcbb935f 2026-03-31
FileHash-SHA256 5cd4280b7b5a655b611702b574b0b48cd46d7729c9bbdfa907ca0afa55971662 2026-03-31
FileHash-SHA256 5eaaf281883f01fb2062c5c102e8ff037db7111ba9585b27b3d285f416794548 2026-03-31
FileHash-SHA256 613ebc1e89409c909b2ff6ae21635bdfea6d4e118d67216f2c570ba537b216bd 2026-03-31
FileHash-SHA256 630dfd5ab55b9f897b54c289941303eb9b0e07f58ca5e925a0fa40f12e752653 2026-03-31
FileHash-SHA256 91ec2ede66c7b4e6d4c8a25ffad4670d5fd7ff1a2d266528548950df2a8a927a 2026-03-31
FileHash-SHA256 a2b9e0887751c3d775adc547f6c76fea3b4a554793059c00082c1c38956badc8 2026-03-31
FileHash-SHA256 a773bf0d400986f9bcd001c84f2e1a0b614c14d9088f3ba23ddc0c75539dc9e0 2026-03-31
FileHash-SHA256 c9e3fdd90e1661c9f90735dc14679f85985df4a7d0933c53ac3c46ec170fdcfd 2026-03-31
FileHash-SHA256 dc3b2db1608239387a36f6e19bba6816a39c93b6aa7329340343a2ab42ccd32d 2026-03-31
FileHash-SHA256 df0136f1d64e61082e247ddb29585d709ac87e06136f848a5c5c84aa23e664a0 2026-03-31