Learn More about Benny Czarny's Book Cybersecurity Upside Down

Learn More
We utilize artificial intelligence for site translations, and while we strive for accuracy, they may not always be 100% precise. Your understanding is appreciated.

How MetaDefender™ Endpoint Stops the Recent WhatsApp VBScript RMM Campaign

By OPSWAT
Share this Post

Security researchers recently uncovered a campaign distributing VBS (Visual Basic Script) files through WhatsApp Desktop and WhatsApp Web. These files are often disguised as routine business documents, with names like "Financial Reports.vbs" or "Account Statement.vbs," designed to persuade recipients to download and open the attachment. The campaign has already reached victims in multiple countries worldwide.

How the Download-Based Malware Attack Was Executed

Attackers gained unauthorized access to WhatsApp accounts and used them to send the disguised files to the account's contacts, exploiting the trust that comes with a message from a known sender. Once opened, the script executes via "WScript.exe" and retrieves additional payloads from a remote server. One weakens the UAC (Windows User Account Control) behavior, and the other downloads and installs ManageEngine RMM (Remote Monitoring and Management) Central, a legitimate IT administration tool that grants the attacker persistent remote access to the device.

The behavior differs by platform. On WhatsApp Web, the file must be opened manually from the downloads folder. On WhatsApp Desktop, the client's own background process, "WhatsApp.Root.exe," was observed spawning "WScript.exe" directly.

Why Download Security Matters

This campaign isn’t specific to a script or an RMM tool. It reveals an often-overlooked entry point through which enterprise systems can be exposed. Employees constantly download files from vendors, clients, coworkers, and from messaging apps that were never designed with enterprise security in mind. Every one of those downloads is a decision point.

Once opened, whatever it contains runs with the user's system permissions. Traditional defenses were not built with this pattern in mind. Network security assumes traffic crosses a perimeter that it can inspect. Antivirus tools largely rely on knowing what malicious software looks like in advance. Neither assumption holds up well against a file that arrives from a trusted contact, mimics an everyday document, and installs a non-malicious piece of software.

Considerations for Security and IT Leaders

The main consideration here isn’t specific to WhatsApp. It is a warning about any channel that an organization has not considered as a file download source. Instant messaging apps, cloud storage links, collaboration tools, and personal email accessed on work devices pose the same threat.

Every file deserves the same scrutiny at the moment of download as at the moment of network entry. Waiting for a file to misbehave after it is already running, or hoping an employee recognizes a disguised script before double-clicking it, puts the outcome in the hands of chance. Controlling what is allowed to execute and assessing every file as soon as it lands on a device removes that gamble.

How MetaDefender Endpoint Secures File Downloads

This is precisely the failure mode that Download Protection, a feature of OPSWAT MetaDefender Endpoint, is built to address. Download Protection inspects files when they are downloaded to a managed endpoint, before they are available to open. MetaDefender Endpoint scans each file through the Metascan™ Multiscanning technology with more than 30 anti-malware engines, including OPSWAT Predictive Alin AI. It also sanitized files with the Deep CDR™ Technology, which proactively disarms file-based threats and regenerates clean, usable files in milliseconds, neutralizing embedded scripts, macros, and unknown malware across 200+ file types.

MetaDefender Endpoint can help organizations secure their critical systems against such download campaigns in the following ways:

  • A disguised VBS file arriving through WhatsApp Web is scanned as it downloads, before the user gets the chance to double-click it.
  • Even drive-by downloads without the user's consent are actively and thoroughly scanned with MetaDefender Endpoint, ensuring only safe, clean files are accessible.
  • A blocked file is deleted automatically rather than remaining available for a second, unsupervised attempt.
  • Because the RMM installer itself is legitimate software, the application control feature in MetaDefender Endpoint lets administrators govern applications running on managed devices and block unwanted applications.

How to Stop Future Malicious Download Campaigns

Such campaigns often go unnoticed because they target downloads rather than the network, using legitimate-looking files and trusted senders. By scanning downloads with MetaDefender Endpoint, organizations can stop attacks like this one before any script runs. This doesn’t prevent employees from using the tools they rely on, including messaging apps, without that convenience becoming the organization's next entry point. Security stops depending on every user making the right call about every file, every time.

To see how Download Protection handles malicious download payload campaigns, talk to an expert today.

Stay Up-to-Date With OPSWAT!

Sign up today to receive the latest company updates, stories, event info, and more.