← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
IOC - WhatsApp malware campaign delivers VBScript and MSI backdoors
Microsoft Defender Experts observed a campaign beginning in late February 2026 that uses WhatsApp messages to deliver malicious Visual Basic Script (VBS) files. Once executed, these scripts initiate a multi-stage infection chain designed to establish persistence and enable remote access.
The campaign relies on a combination of social engineering and living-off-the-land techniques. It uses renamed Windows utilities to blend into normal system activity, retrieves payloads from trusted cloud services such as AWS, Tencent Cloud, and Backblaze B2, and installs malicious Microsoft Installer (MSI) packages to maintain control of the system. By combining trusted platforms with legitimate tools, the threat actor reduces visibility and increases the likelihood of successful execution.
Indicators of Compromise (3 / 23 total)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-MD5 | 1304f43c5fddcf664ba0f068a5a7bc18 | MD5 of 1735fcb8989c99bc8b9741f2a7dbf9ab42b7855e8e9a395c21f11450c35ebb0c | 2026-04-01 | |
| FileHash-MD5 | 2d9ef700fb9ce1550ca73f50428fef87 | MD5 of a2b9e0887751c3d775adc547f6c76fea3b4a554793059c00082c1c38956badc8 | 2026-04-01 | |
| FileHash-MD5 | 3466746d84501cb07a9833057e835565 | MD5 of 57bf1c25b7a12d28174e871574d78b4724d575952c48ca094573c19bdcbb935f | 2026-04-01 |