HackMyIP
← Back to News
2026-06-23 The Hacker News

WhatsApp VBScript Campaign Drops ManageEngine RMM via Fake Documents

MalwarePhishingThreat Intel

Security researchers at Kaspersky have uncovered an active social engineering campaign abusing WhatsApp Direct Messages to distribute heavily obfuscated VBScript files disguised as routine business and financial documents. The malicious attachments, named things like "Financial Reports.vbs" and "Account Statement.vbs" (with additional variants in Portuguese, French, German, and Malay), trick recipients into launching a multi-stage infection chain that ultimately installs legitimate ManageEngine Remote Monitoring and Management (RMM) software on the victim's machine. The campaign has been observed targeting WhatsApp Desktop and WhatsApp Web users across Malaysia, Brazil, India, Mexico, Singapore, the U.K., Spain, Taiwan, Australia, Russia, and Vietnam, with Malaysia reporting the highest concentration of victims. According to researcher Fareed Radzi, the threat actor is believed to have compromised multiple WhatsApp accounts first, then used them as trusted distribution vectors to spread the payloads across each victim's contact list—though the exact initial access method remains unclear. Users concerned about compromised messaging accounts can verify exposure using an email breach checker and rotate any reused credentials with the help of a password strength checker.

The VBScript samples are crafted with extensive Chinese-language comments and metadata designed to mimic legitimate Microsoft Windows Update components, referencing certificate validation, system integrity checks, and deployment functions in an attempt to evade suspicion. Execution begins via WScript.exe, which fetches two secondary VBScript payloads from a remote server. One payload attempts to tamper with Windows User Account Control (UAC) behavior to suppress security prompts, while the second downloads and executes a ZIP archive containing the ManageEngine RMM Central installer. The infection flow differs slightly between platforms: WhatsApp Web victims must manually download and open the file from their browser's download history, whereas WhatsApp Desktop users see the script launched in-app, with the process tree showing the client's "WhatsApp.Root.exe" background process spawning WScript.exe directly.

Once ManageEngine RMM is installed, the attacker gains persistent remote access to the endpoint, effectively converting a trusted messaging app into a beachhead for further intrusion. Because the deployed tool is legitimate signed software, its presence is unlikely to be flagged by traditional antivirus products, giving the operator a stealthy foothold inside corporate and personal environments alike. Kaspersky has not yet attributed the campaign to a specific threat actor, but the use of Chinese-language code comments, the multilingual lure document names, and the global targeting footprint suggest a financially motivated operator testing RMM-based access across diverse regions. Organizations should audit any unexpected ManageEngine RMM installations, monitor outbound traffic from RMM agents to non-corporate infrastructure, and review the privacy checkup posture of endpoints that handle sensitive financial communications over WhatsApp.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Auth Check →Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

How phishing attacks work →How to check if an email is safe →SPF, DKIM & DMARC explained →