PULSE NAME
IOC - WhatsApp malware campaign delivers VBScript and MSI backdoors
WHITE celestre 2026-04-01 Modified: 2026-04-01
23
IOCs
MEDIUM VOLUME
Microsoft Defender Experts observed a campaign beginning in late February 2026 that uses WhatsApp messages to deliver malicious Visual Basic Script (VBS) files. Once executed, these scripts initiate a multi-stage infection chain designed to establish persistence and enable remote access. The campaign relies on a combination of social engineering and living-off-the-land techniques. It uses renamed Windows utilities to blend into normal system activity, retrieves payloads from trusted cloud services such as AWS, Tencent Cloud, and Backblaze B2, and installs malicious Microsoft Installer (MSI) packages to maintain control of the system. By combining trusted platforms with legitimate tools, the threat actor reduces visibility and increases the likelihood of successful execution.
Indicators of Compromise (3 / 23 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 1304f43c5fddcf664ba0f068a5a7bc18 MD5 of 1735fcb8989c99bc8b9741f2a7dbf9ab42b7855e8e9a395c21f11450c35ebb0c 2026-04-01
FileHash-MD5 2d9ef700fb9ce1550ca73f50428fef87 MD5 of a2b9e0887751c3d775adc547f6c76fea3b4a554793059c00082c1c38956badc8 2026-04-01
FileHash-MD5 3466746d84501cb07a9833057e835565 MD5 of 57bf1c25b7a12d28174e871574d78b4724d575952c48ca094573c19bdcbb935f 2026-04-01