WhatsApp-Distributed VBScript Campaign Deploying ManageEngine Endpoint Central RMM for Persistent Remote Access — Threadlinqs Intelligence
As of 2026-06-22, WhatsApp-Distributed VBScript Campaign Deploying ManageEngine Endpoint Central RMM for Persistent Remote Access is a high-severity malware threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 36 indicators of compromise.
Threat ID: TL-2026-0899 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
An unattributed, likely Chinese-speaking threat actor distributes obfuscated VBScript/VBE files via WhatsApp using financial-themed lures, running a three-stage chain that bypasses UAC and silently
Securelist (Kaspersky) documented an active campaign in which a threat actor abuses the legitimate ManageEngine Endpoint Central (Unified Endpoint Management & Security, UEMS) remote monitoring and management agent as an implant for unauthorized, persistent remote access. Initial access is achieved through social engineering on WhatsApp: malicious VBScript (.vbs) and VBE files are sent as direct-message attachments with financial-themed filenames (e.g. "Financial Reports.vbs", "Outstanding Payment List.vbs", "Statement of Debt(30K).vbs") localized into multiple languages (English, Portuguese, French, German, Malay). On WhatsApp Desktop the script executes directly, spawning WScript.exe as a child of WhatsApp.Root.exe; on WhatsApp Web the victim must open the downloaded file manually.
Stage 1: the initial heavily-obfuscated VBScript (string concatenation, character-by-character path building, junk-code padding, extension spoofing of PDF/TXT to VBS, and renamed copies of curl.exe/bitsadmin.exe given DLL-like names) creates randomized hidden+system working directories under C:\Users\Public\Documents\ (patterns like Temp_<random>, MSUpdate_<random>, Sys<random>) and downloads two further VBScript payloads from remote infrastructure, executing them via Windows Script Host.
Stage 2: the first secondary payload performs a UAC bypass by repeatedly writing 0 to HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\ConsentPromptBehaviorAdmin in a short-delay loop and invoking ShellExecute with the runas verb to obtain elevation. The second secondary payload downloads a ZIP archive using multiple redundant fetch mechanisms (curl, bitsadmin, certutil, PowerShell, direct HTTP), then extracts it via the Shell.Application CopyHere method with flags that suppress prompts; one variant strips Zone.Identifier alternate data streams to bypass Mark-of-the-Web warnings.
Stage 3: the ZIP contains a preconfigured ManageEngine Endpoint Central deployment package (DCAgentServerInfo.json, DMRootCA.crt, DMRootCA-Server.crt, UEMSAgent.msi, UEMSAgent.mst, setup1.vbs, README.html). setup1.vbs verifies the files, requests admin rights via runas, then silently installs the bundled UEMS agent with msiexec.exe using the attacker-supplied configuration and certificates, enrolling the victim host into attacker-controlled Endpoint Central servers for persistent remote control.
The campaign targets individual consumers rather than specific organizations; ~80% of observed victims are in Malaysia. Attribution is low confidence: multiple samples contain simplified-Chinese comments/module descriptions and Windows-Update-themed notes, and the management server 202.61.160.201 was previously seen as C2 for ValleyRAT and Gh0st RAT, suggesting a possible Chinese-speaking actor but insufficient evidence for confident attribution.
Target sectors: consumer, general public
Target regions: Malaysia, Brazil, India, Mexico, Singapore, United Kingdom, Spain, Taiwan, Australia, Russia, Vietnam
Detections & IOCs
As of 2026-07-26, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 36 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
1 of this threat's indicators have also been reported by the open-source security community. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
MALWARE, HIGH, threat intelligence, cybersecurity, T1583, T1608, T1566, T1204, T1059, T1059, T1218, T1543, T1548, T1140