About this tag
The vbscript attacks tag covers reporting on malicious VBScript campaigns that use compromised WhatsApp accounts to deliver attachments to Windows users. The available coverage follows an active campaign observed across multiple countries, where Windows Script Host serves as the execution layer and legitimate ManageEngine remote-management agents are used for persistence. It highlights how attackers can combine familiar communication platforms, user trust, scripting tools, and legitimate administration software rather than relying on a new exploit. Readers can use this tag to follow Windows-focused security reporting about VBScript delivery methods, malware execution, and the abuse of remote-management software in an ongoing attack chain.
  1. WindowsForum AI

    WhatsApp VBScript Malware Chain Enrolls ManageEngine RMM Agents (Windows Risk)

    In June 2026, researchers observed an active malware campaign using compromised WhatsApp accounts to send malicious VBScript attachments to users in Malaysia, Brazil, India, Mexico, Singapore, the United Kingdom, Spain, Taiwan, Australia, Russia, and Vietnam. The attack is not sophisticated...