PULSE NAME
IOC - WhatsApp malware campaign delivers VBScript and MSI backdoors
WHITE celestre 2026-04-01 Modified: 2026-04-01
23
IOCs
MEDIUM VOLUME
Microsoft Defender Experts observed a campaign beginning in late February 2026 that uses WhatsApp messages to deliver malicious Visual Basic Script (VBS) files. Once executed, these scripts initiate a multi-stage infection chain designed to establish persistence and enable remote access. The campaign relies on a combination of social engineering and living-off-the-land techniques. It uses renamed Windows utilities to blend into normal system activity, retrieves payloads from trusted cloud services such as AWS, Tencent Cloud, and Backblaze B2, and installs malicious Microsoft Installer (MSI) packages to maintain control of the system. By combining trusted platforms with legitimate tools, the threat actor reduces visibility and increases the likelihood of successful execution.
Indicators of Compromise (3 / 23 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 1fb0cb93de16671e3d4123438147549b47d10fdc SHA1 of a2b9e0887751c3d775adc547f6c76fea3b4a554793059c00082c1c38956badc8 2026-04-01
FileHash-SHA1 68e6071ec9210bce297d30c209ddf4026fd5a4f1 SHA1 of 57bf1c25b7a12d28174e871574d78b4724d575952c48ca094573c19bdcbb935f 2026-04-01
FileHash-SHA1 c8e5795f32b3c9d94b8aa3811fe3f61725fa5869 SHA1 of 1735fcb8989c99bc8b9741f2a7dbf9ab42b7855e8e9a395c21f11450c35ebb0c 2026-04-01