惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

MongoDB | Blog
MongoDB | Blog
Recorded Future
Recorded Future
Jina AI
Jina AI
The Register - Security
The Register - Security
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
月光博客
月光博客
博客园 - 三生石上(FineUI控件)
F
Fortinet All Blogs
人人都是产品经理
人人都是产品经理
S
SegmentFault 最新的问题
Apple Machine Learning Research
Apple Machine Learning Research
L
LangChain Blog
Y
Y Combinator Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
GbyAI
GbyAI
The GitHub Blog
The GitHub Blog
Vercel News
Vercel News
博客园 - 【当耐特】
雷峰网
雷峰网
The Cloudflare Blog
阮一峰的网络日志
阮一峰的网络日志
aimingoo的专栏
aimingoo的专栏
云风的 BLOG
云风的 BLOG
I
InfoQ
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Google DeepMind News
Google DeepMind News
Security Latest
Security Latest
有赞技术团队
有赞技术团队
L
Lohrmann on Cybersecurity
P
Proofpoint News Feed
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
The Last Watchdog
The Last Watchdog
P
Privacy & Cybersecurity Law Blog
Scott Helme
Scott Helme
Google Online Security Blog
Google Online Security Blog
WordPress大学
WordPress大学
Hacker News - Newest:
Hacker News - Newest: "LLM"
NISL@THU
NISL@THU
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
B
Blog RSS Feed
Cyberwarzone
Cyberwarzone
K
Kaspersky official blog
F
Full Disclosure
Martin Fowler
Martin Fowler
Spread Privacy
Spread Privacy
D
Docker
C
Cisco Blogs
www.infosecurity-magazine.com
www.infosecurity-magazine.com
H
Hacker News: Front Page

Cyber Security News

AIRecon: AI-Powered Penetration Testing Tool with Kali Linux Sandbox Critical Chrome Vulnerabilities Allow Attackers to Execute Arbitrary Code - Update Now! UNC3753 Uses Screen-Sharing Sessions and RMM Tools to Exfiltrate Sensitive Legal Data New OnionDrop Loader Campaign Uses gainmsg C2 to Deliver LegionLoader Payloads ClickFix Campaign Uses EtherHiding and GULoader to Infect Windows Users via Fake CAPTCHA Ghostwriter Hackers Abuse Gmail Admin-Themed Emails to Steal Credentials and 2FA Codes The Half-Life of Threat Intelligence: When Does an IOC Stop Being Useful? Critical Fortinet FortiSandbox Vulnerabilities Actively Exploited in Attacks Aembit Extends IAM for Agentic AI to Microsoft Copilot Studio India Temporarily Bans Telegram Messenger Over Medical Exam Fraud Microsoft 365 Device Code Phishing Campaign Bypasses Password Theft With Legitimate Login Flow AppViewX Launches Agent Identity Security to Govern Agents for the AI and Quantum Era Hackers Weaponize Microsoft Teams Relay to Hide Ransomware Traffic Developer laptops are the credential store attackers are picking through in 2026, GitGuardian announces Endpoint Protection Interlock and Rhysida Ransomware Operations Share Supper Backdoor and Malware Codebase Novo Nordisk Confirms Cyber Attack — Hackers Accessed Patient Medical Data and Internal AI Assets Russian and Chinese Influence Actors Use AI to Evade Bot Detection and Mimic Human Behavior Microsoft Teams Analyze the Wi-Fi Hotspot Data Connected to an Employee’s Device PRC-Nexus Hackers Exploit REDCap Servers to Spy on US Medical Research Institutions Infinite Campus Data Breach Exposes 137,000 Users Personal Details OptinMonster Plugin Hack Exposes 1.2 Million Wordpress Sites to Cyberattack Ransomware Ecosystem Consolidates Around LockBit Alumni, Qilin, Hyflock, and The Gentlemen Hackers Abuse Legitimate RMM Tools in The Quarry IRS and SSA Phishing Campaigns LiteSpeed cPanel Plugin 0-Day Vulnerability Actively Exploited in the Wild Cisco SD-WAN vManage Vulnerability Exploited in Zero-Day Attacks Nearly 14,000 SimpleHelp Servers Exposed Amid Critical Authentication Bypass Disclosure Microsoft Site Showing Warning Following Certificate Expiry DPAPISnoop Tool Extracts CREDHIST Hashes for Offline Windows Credential Recovery SHADOWBYT3$ Allegedly Claim Breach of Nintendo, Stealing Sensitive Data Anthropic Updated Privacy Policy to Include Identity Verification for Claude Users Critical Microsoft 365 Copilot Vulnerability Allows Attackers to Steal Data in One Click Hackers Use Microsoft Graph Reconnaissance to Target Payroll and HR Employees China-Nexus Hackers Use Backdoored PAM Modules for Credential Theft and Authentication Bypass SearchJack Campaign Uses 23 Chrome Extensions to Hijack Searches of 758,000 Users PromptSnatcher Ad Blocker Extensions Steal AI Chats From ChatGPT, Claude, and Gemini Hackers Abuse LNK Files, PowerShell, and Python Loader to Deploy NarwhalRAT Windows 11 Update KB5094126 Freezes Systems, Forces BitLocker Recovery, and More Critical Wazuh Vulnerability Lets Attackers Tamper with Alerts and Delete Security Evidence SecSuite - AI-powered Tool for OSINT, Web and API Security Testing WinRAR Vulnerability Exploited by Russian Hackers to Deploy GIFTEDCROOK Stealer Palo Alto Warns of GlobalProtect VPN Vulnerability Actively Exploited in the Wild Threat Actor Malware Platform Exposed via Unlocked PHP Installation Page Criminal IP at Infosecurity Europe 2026: Introducing AITEM, the Next Chapter of Attack Surface Management Maine Takes Data Breach Reporting Portal Offline After Fake VRChat and Discord Filings 152 Chrome Extensions Hide Ad Tracking and Fake Google Search Traffic New Agentjacking Attack Hijacks Your AI Coding Agent to Run Code From Hackers Server BugHunter - Bug Bounty Toolkit Powered by Claude and Free AI Providers Splunk Enterprise Pre-Auth RCE Chain Exposes Database With Zero Authentication Anthropic Fable 5 and Mythos 5 Access Blocked to All Users Following Government Directive Fancy Bear Hackers Abuse EdgeRouters and Cloud Services to Launch Stealthy Cyberattacks Hackers Abuse Legitimate NinjaOne RMM Software to Bypass Traditional Malware Detection Malicious npm Campaign Steals SSH Keys, API Tokens, Cloud Credentials, and Wallet Secrets Hackers Use OnyxC2 Malware-as-a-Service to Steal Credentials From 210 Applications Facebook and Instagram Down Globally, Users Reporting Multiple Issues Google Sues Chinese Cybercrime Network for Using Gemini AI to Launch Cyberattacks 400+ Arch Linux AUR Packages Compromised in a Supply Chain Attack Deploying Infostealers Critical Vulnerability Chain in LangGraph Allows Attackers to Gain Full Server Control SHEETCREEP C# RAT Abuses Google Sheets API as C2 to Target Diplomatic Organizations Authorities Dismantle Cryptocurrency Laundering Services ‘AudiA6’ Used by Ransomware Gangs Hackers Use Free Spotify Premium Hacks on TikTok and Instagram to Spread Vidar Infostealer Solana FakeFix Campaign Uses 25 Malicious npm and PyPI Packages to Steal Developer Secrets Microsoft Outlook and Word Vulnerabilities Allow Attackers to Execute Malicious Code Palo Alto PAN-OS Vulnerability Allows Attackers to Execute Arbitrary Commands as Root User Google Patches 28 Chrome Vulnerabilities that Allow Attackers to Execute Malicious Code Microsoft Teams for Android Vulnerability Allows Attackers to Disclose Sensitive Data Oracle PeopleSoft 0-Day RCE Vulnerability Exploited in Attacks by ShinyHunters CISA Requires Federal Agencies to Patch Critical Vulnerabilities Within 3 Days OceanLotus APT Compromises FireAnt MetaKit in Supply-Chain Attack on Stock Investors GoFlateLoader Uses Massive PE Overlay to Deliver Lumma, Vidar, and StealC Infostealers Critical Langflow Vulnerability Exploited to Execute Malicious Code Hackers Abuse SniperDz PhaaS Ecosystem for Brand Impersonation and Browser Hijacking Researcher Hacked Google Using AI and Earned $500,000 Bug Bounty GitHub to Automate Disable npm Script Installs to Block Supply Chain Attacks Claude Mythos Turning N-Days Into N-Hours With Rapid Working Exploit Creation CISA Warns of Check Point Security Gateway Vulnerability Actively Exploited in Ransomware Attacks Hackers Use Weaponized DMG Files to Target macOS Users With Infostealer Malware Hackers Use BLUERABBIT Backdoor to Encrypt Files and Wipe Disks Across Windows Systems Hackers Abuse Residential Proxy Networks to Hide Malicious Activity and Evade Detection Cybercriminals Abuse Chinese-Language Guarantee Marketplaces to Trade Stolen Credentials Ivanti Command Injection Vulnerability Exploited in Attacks Following PoC Release PoC Exploit Released for Guest-to-Host Escape Linux Kernel Vulnerability Oracle Emergency Security Update to Fix Critical RCE Vulnerability GreatXML BitLocker Bypass 0-Day Exploited Via Windows Defender Offline Scan Hackers Abuse VMware-Signed Binary to Sideload NIGHTFORGE Loader in Espionage Attacks Multiple Splunk Enterprise Vulnerabilities Allow Attackers to Execute Malicious Script Hackers Abuse AWS CloudTrail and Google Cloud Logging to Evade Detection and Exfiltrate Logs China-Linked JDY Botnet Uses 1,500+ SOHO and IoT Devices for Rapid Vulnerability Exploitation CISA Warns of SolarWinds Serv-U Vulnerability Exploited in Attacks Top 5 Best Tools for Simulated DDoS Attacks in 2026 Critical Vulnerability in Hugging Face Transformers Enables Remote Code Execution Attacks OWASP CVE Lite CLI - New Tool to Scan for Vulnerabilities in Your Projects Anthropic's Claude Services Down — claude.ai, Claude Code, and Cowork Affected [Updated] Hackers Publish Malicious Python Package Mimicking Legitimate Parsimonious Parser Hackers are Increasingly Weaponizing Trusted Tools to Deploy Notorious Malware New Magecart Attack Turns Stripe into a Malware Command Server Hola Browser for Windows Delivery Pipeline Compromised to Deliver Cryptominer New Gafgyt Variant Targets Multiple Linux Architectures With Modular Propagation Microsoft 365 Service Degradation Bypassed Windows Driver Auto-Update Controls New SHub Stealer Variant Malware Targets Chrome, Firefox, Brave, Edge, Opera, and Crypto Wallets Malicious Browser Add-Ons Target ChatGPT, Claude, Copilot, Gemini, and DeepSeek Users
New Malware Attack Via WhatsApp Attacking Windows System to Enable Remote Access For Attackers
Tushar Subhra Dutta · 2026-06-22 · via Cyber Security News

A new and active malware campaign is spreading through WhatsApp, targeting everyday Windows users across more than a dozen countries.

The threat uses malicious script files disguised as routine financial documents, tricking people into running harmful code on their own machines.

Once opened, the file quietly sets off a chain of events that ends with attackers gaining full remote access to the victim’s system.

The campaign was first observed in June 2026 and remains active at the time of reporting. Victims have been identified in Malaysia, Brazil, India, Mexico, Singapore, the United Kingdom, Spain, Taiwan, Australia, Russia, and Vietnam.

Malaysia has been hit the hardest, accounting for roughly 80 percent of all recorded infections. Researchers at Securelist identified and analyzed the campaign in detail.

According to Securelist report shared with Cyber Security News (CSN), the threat actor behind this campaign gained access to real WhatsApp accounts and used them to silently send malicious attachments to everyone in the compromised contact lists.

Since the messages appeared to come from known contacts, recipients were far more likely to open them without suspicion.

Overview of the WhatsApp-based VBScript infection chain (Source - Securelist)
Overview of the WhatsApp-based VBScript infection chain (Source – Securelist)

The attachments are VBScript files, a type of script that Windows can run automatically through a built-in tool called Windows Script Host.

The files carried names like “Financial Reports.vbs,” “Debt Statement.vbs,” and “Account Statement.vbs,” along with versions written in Portuguese, French, German, and Malay.

This multi-language approach strongly suggests the campaign was designed to reach victims in several regions at once.

What makes this attack stand out is its use of legitimate software as the final payload. Rather than deploying a traditional virus or data stealer, the attacker installs a genuine remote management tool on the victim’s machine.

This allows the attacker to control the infected system just like a corporate IT team would, making detection far more difficult.

New Malware Attack Via WhatsApp Attacking Windows System

The infection begins the moment a user opens the VBScript attachment in WhatsApp Desktop or through a browser using WhatsApp Web.

WhatsApp messages containing the malicious VBScript file observed across multiple accounts (Source - Securelist)
WhatsApp messages containing the malicious VBScript file observed across multiple accounts (Source – Securelist)

The script launches silently through Windows Script Host and immediately begins preparing the system for further compromise.

It creates a hidden folder under the Public Documents directory using randomized names like “MSUpdate_random” to avoid attracting attention.

From there, the first script downloads two additional script files from attacker-controlled servers. The first of these tries to modify a Windows security setting known as User Account Control, which normally alerts users before any major system changes are made.

By setting this protection to zero, the attacker clears the path for the second script to install software without any prompts appearing on screen.

The second downloaded script fetches a ZIP archive containing a fully pre-configured installation package for a remote management agent.

Once extracted and executed, this package installs itself silently using Windows Installer and connects back to attacker-controlled servers. At that point, the attacker has persistent and quiet remote access to everything on the victim’s machine.

Signs Pointing to a Chinese-Speaking Operator

Security researchers noted several details within the script files that point toward a Chinese-speaking developer.

Multiple variants of the VBScript contained comments and annotations written in simplified Chinese characters, including references to Windows Update modules and system integrity checks. These comments appeared consistently across different versions of the script.

Infrastructure overlaps also raised flags. One of the attacker-controlled server addresses had previously appeared in connection with malware families known as ValleyRAT and Gh0st RAT.

Extracted Stage 3 Endpoint Central installation ZIP package (Source - Securelist)
Extracted Stage 3 Endpoint Central installation ZIP package (Source – Securelist)

While this does not confirm a definitive link, researchers assess with low confidence that the campaign was likely conducted by a Chinese-speaking operator.

Users are strongly advised to avoid opening any attachments received through WhatsApp, even from known contacts, unless the file has been verified through another channel.

Endpoint Central agent installation via msiexec.exe (Source - Securelist)
Endpoint Central agent installation via msiexec.exe (Source – Securelist)

File types such as VBS, VBE, EXE, BAT, CMD, JS, and PS1 should never be opened without independent confirmation.

Keeping Windows security settings intact and running current endpoint protection can significantly reduce the risk of falling victim to campaigns like this one.

Indicators of Compromise (IoCs):-

TypeIndicatorDescription
IP Address202.61.160[.]208Attacker-controlled ManageEngine UEMS server
IP Address202.61.160[.]202Attacker-controlled ManageEngine UEMS server
IP Address202.61.160[.]201Attacker-controlled ManageEngine UEMS server (previously linked to ValleyRAT/Gh0st RAT)
IP Address202.61.160[.]160Attacker-controlled ManageEngine UEMS server
IP Address202.61.160[.]137Attacker-controlled ManageEngine UEMS server
IP Address38.55.151[.]63Attacker-controlled ManageEngine UEMS server
Domaintemu.baskwms[.]topMalware distribution domain
Domaininvoice.msopsa[.]topMalware distribution domain
Domainbaoxis[.]ccMalware distribution domain
Domainsdcwww.oss-ap-southeast-1.aliyuncs[.]comPayload hosting (Alibaba Cloud)
Domainbaoyuw2s.s3.ap-southeast-1.amazonaws[.]comPayload hosting (AWS S3)
Domainsjdkjj23.s3.ap-southeast-1.amazonaws[.]comPayload hosting (AWS S3)
Domainxijkwm2.s3.ap-southeast-1.amazonaws[.]comPayload hosting (AWS S3)
Domainyifubafu.s3.ap-southeast-1.amazonaws[.]comPayload hosting (AWS S3)
File Hash (MD5)c7f38cbb99c8b74fa0465293feeba700Financial Reports.vbs
File Hash (MD5)b7cd06c71465038b658a6dc1f273a507Debt confirmation.vbs
File Hash (MD5)9f13c7b8ba391b2f597874e54d310648Electronic statement(A).vbs
File Hash (MD5)993f4c0cadbc769a4b0ed62a918db58dFinancial Reports(s).vbs / FinancialReportsS.vbs
File Hash (MD5)7f81c1bc8cfd588e8998968e2621456eOutstanding Payment List.vbs
File Hash (MD5)7403cbcc5a9c32384d431856dc48fcc9Statement of debt (4).vbs
File Hash (MD5)68c16c46f8afb9e00bbaba0207fb0a46Debt Note (2).vbs
File Hash (MD5)66442f2457eca8f47385b1fb2c6fcab8Statement of Debt(30K).vbs
File Hash (MD5)6359e6236471cbe434d0ef4c42b7f879Applicationform1.vbs
File Hash (MD5)5b6bbcc06cf08cc99e1afeda486d42fbExtrato de Conciliação.vbs
File Hash (MD5)5002eca748205d544618e3bd2dedc223Statement of Debt(29K).vbs
File Hash (MD5)4f0593e8e0e8fac49429e9b45ebf7fa1Outstanding Payment List.vbs
File Hash (MD5)4044e4b6471c9de7b0a4ba37d9d9df9abilling statement (2).vbs
File Hash (MD5)20209b3a32769afc6a75694b8d8839ddStatement of Debt(A).vbs
File Hash (MD5)0ba93109757776a44de9d8c88baa4963Financial Reports(C1).vbs
File Hash (MD5)02bb20455cc592a69c080abac770ce90Le formulaire de demande le plus récent.vbs
File Hash (MD5)6c39900d77dcba158e1d27c7619cb06dOutstanding Balance Sheet(A).vbs
File Hash (MD5)dad708e050632a4280cabf98ac1376b7Outstanding Balance Sheet.vbs
File Hash (MD5)05d188f071d097f5b6bd8138749b4b14Penyata bank.vbs
File Hash (MD5)2c6f05f1f309d89b2236e6c8b59c88f9Account Statement (13K) (2).vbs
File Hash (MD5)3b1aba44dd3d9b6339b6f56e2f42034bStatement of Account.txt
File Hash (MD5)d43fdaa1f0ee09d7e5f0f94ee9df7b6cBitte füllen Sie das Formular…aus.vbs
File Hash (MD5)df4fa0369eaca5cec348be293890d4afAccount Statement.vbs
File Hash (MD5)63ac85195b73753333316a889cf5880fStatement of Account(O).vbs
File Hash (MD5)74fd9f91fc93b6288b4fc253ea5b3e20Sila semak bil anda.vbs
File Hash (MD5)d06333c360b51456f427e616c3c5f8bdSila semak bil anda.vbs (variant)
File Hash (MD5)1d94fbe9cab21278cc3f104bea334d08Promissory_Note(b).vbs
File Hash (MD5)9d9ac85765e4a818a3ccabe2cf4fef82Debt Statement.vbs
File Hash (MD5)6fb6a55424adfb61e31f06aef33273e5dfjieya.vbs
File Hash (MD5)f90ed4b2d0b67114aa89ddfed658e5c0dfjieya.vbs (variant)
File Hash (MD5)8c3322009b8982663c0cbecd9492e7eb0lf.vbs
File Hash (MD5)66705384a7ad81d14c34fc6c054a0ecfiowepv.vbs
File Hash (MD5)8c6d9fc389ad3f20ccbc71d77eb39bfabtksfmsi.vbs
File Hash (MD5)1a3cc75466ffb1971482f7abf7aabc3fhome3.vbs
File Hash (MD5)1c47c63e5ed25060d95359c57c77b107zipats.vbs
File Hash (MD5)31037a42ca048e06e69a78f55bc2eff51122.vbs
File Hash (MD5)7f16449cd0c4862d1eadf8a5742bf09apayload_1.vbs
File Hash (MD5)79ecd61b09b0f2d54b34586c916c4ec9sac8.vbs
File Hash (MD5)7849061c536a3efb05a56d504694e7e76oy.vbs
File Hash (MD5)ddaffe9849f7f3c79f8804adb9a6b3d5kof.vbs
File Hash (MD5)d01cad98dd0d01b75e04e784953c5e2bsleestak_payload_1.vbs

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

Tushar Subhra Dutta

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.