PULSE NAME
IOC - WhatsApp malware campaign delivers VBScript and MSI backdoors
WHITE celestre 2026-04-01 Modified: 2026-04-01
23
IOCs
MEDIUM VOLUME
Microsoft Defender Experts observed a campaign beginning in late February 2026 that uses WhatsApp messages to deliver malicious Visual Basic Script (VBS) files. Once executed, these scripts initiate a multi-stage infection chain designed to establish persistence and enable remote access. The campaign relies on a combination of social engineering and living-off-the-land techniques. It uses renamed Windows utilities to blend into normal system activity, retrieves payloads from trusted cloud services such as AWS, Tencent Cloud, and Backblaze B2, and installs malicious Microsoft Installer (MSI) packages to maintain control of the system. By combining trusted platforms with legitimate tools, the threat actor reduces visibility and increases the likelihood of successful execution.
Indicators of Compromise (16 / 23 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 07c6234b02017ffee2a1740c66e84d1ad2d37f214825169c30c50a0bc2904321 2026-04-01
FileHash-SHA256 15a730d22f25f87a081bb2723393e6695d2aab38c0eafe9d7058e36f4f589220 2026-04-01
FileHash-SHA256 1735fcb8989c99bc8b9741f2a7dbf9ab42b7855e8e9a395c21f11450c35ebb0c 2026-04-01
FileHash-SHA256 1f726b67223067f6cdc9ff5f14f32c3853e7472cebe954a53134a7bae91329f0 2026-04-01
FileHash-SHA256 22b82421363026940a565d4ffbb7ce4e7798cdc5f53dda9d3229eb8ef3e0289a 2026-04-01
FileHash-SHA256 57bf1c25b7a12d28174e871574d78b4724d575952c48ca094573c19bdcbb935f 2026-04-01
FileHash-SHA256 5cd4280b7b5a655b611702b574b0b48cd46d7729c9bbdfa907ca0afa55971662 2026-04-01
FileHash-SHA256 5eaaf281883f01fb2062c5c102e8ff037db7111ba9585b27b3d285f416794548 2026-04-01
FileHash-SHA256 613ebc1e89409c909b2ff6ae21635bdfea6d4e118d67216f2c570ba537b216bd 2026-04-01
FileHash-SHA256 630dfd5ab55b9f897b54c289941303eb9b0e07f58ca5e925a0fa40f12e752653 2026-04-01
FileHash-SHA256 91ec2ede66c7b4e6d4c8a25ffad4670d5fd7ff1a2d266528548950df2a8a927a 2026-04-01
FileHash-SHA256 a2b9e0887751c3d775adc547f6c76fea3b4a554793059c00082c1c38956badc8 2026-04-01
FileHash-SHA256 a773bf0d400986f9bcd001c84f2e1a0b614c14d9088f3ba23ddc0c75539dc9e0 2026-04-01
FileHash-SHA256 c9e3fdd90e1661c9f90735dc14679f85985df4a7d0933c53ac3c46ec170fdcfd 2026-04-01
FileHash-SHA256 dc3b2db1608239387a36f6e19bba6816a39c93b6aa7329340343a2ab42ccd32d 2026-04-01
FileHash-SHA256 df0136f1d64e61082e247ddb29585d709ac87e06136f848a5c5c84aa23e664a0 2026-04-01