[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fO5S1ps1cxtkMfYjv_TFYYQkqD4dhVzC756jbnP2WIcA":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":49},"40710326-0a3f-4455-9a14-eecebe46c553","malicious-vbscript-spread-via-whatsapp-installs-rmm-tools-for-remote-access","8dcd2ae1-aeef-4f8a-ae94-d3e16b58fb98","Malicious VBScript Spread via WhatsApp Installs RMM Tools for Remote Access","This campaign exploits a fundamental gap in user security awareness: victims are deceived by financial-themed file names into executing malicious VBScript files received over WhatsApp, a platform they inherently trust for personal communication. Once executed, the script silently installs legitimate RMM software, giving attackers full remote access while blending in with normal IT tooling — making detection especially difficult. The abuse of legitimate RMM software is particularly dangerous because it bypasses many traditional security controls that focus on overtly malicious payloads. This attack chain highlights that social engineering through consumer messaging platforms is a significant and underestimated enterprise threat vector.","**Immediate actions:**\n- Block or restrict execution of script file types (`.vbs`, `.js`, `.wsf`) via Group Policy or endpoint security controls.\n- Deploy application allowlisting to prevent unauthorized RMM software from being installed by end users.\n- Notify users immediately about this campaign with concrete examples of the deceptive financial-themed file names being used.\n\n**Long-term improvements:**\n- Establish and enforce a policy prohibiting the execution of files received through personal messaging platforms (WhatsApp, Telegram, etc.) on corporate devices.\n- Conduct regular phishing and social engineering awareness training that explicitly includes messaging-app-based lure scenarios.\n- Maintain an approved inventory of RMM tools and alert on installation or execution of any unapproved remote access software.\n\n**Detection measures:**\n- Monitor endpoint telemetry for unexpected VBScript execution and flag any processes spawned from messaging application directories.\n- Set up alerts for installation or first-run execution of known RMM tools (e.g., AnyDesk, ConnectWise, Atera) that are not sanctioned by IT.\n- Centralize and review logs for outbound connections to RMM vendor relay infrastructure from non-IT endpoints.",[12,13,14,15,16,17,18,19,20,21,22],"CIS Control 2 – Inventory and Control of Software Assets","CIS Control 9 – Email and Web Browser Protections","CIS Control 14 – Security Awareness and Skills Training","CIS Control 18 – Penetration Testing","NIST SP 800-53 SI-3 – Malicious Code Protection","NIST SP 800-53 AT-2 – Literacy Training and Awareness","NIST SP 800-53 CM-7 – Least Functionality","NIST SP 800-53 AU-6 – Audit Record Review, Analysis, and Reporting","MITRE ATT&CK T1059.005 – Command and Scripting Interpreter: Visual Basic","MITRE ATT&CK T1219 – Remote Access Software","GDPR Article 32 – Security of Processing (organizational measures to mitigate human-factor risks)","published","2026-06-22T12:21:44.440071+00:00","2026-06-22T12:21:44.322+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fsecurelist.com\u002Fwhatsapp-vbs-rmm-campaign\u002F120290\u002F","a-vbscript-campaign-distributed-through-whatsapp-deploying-rmm-software-b54b22","A VBScript campaign distributed through WhatsApp deploying RMM software",[31,37,43],{"id":32,"name":33,"slug":34,"description":35,"color":36},"1732a005-556e-411c-a9db-5edec3058571","Logging & Monitoring","logging-monitoring","Missing logs, no alerting, blind spots","#a855f7",{"id":38,"name":39,"slug":40,"description":41,"color":42},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":44,"name":45,"slug":46,"description":47,"color":48},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",[]]