Threats Tagged 'vbs'
View all threats tagged with 'vbs'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'vbs'
Click on any threat for detailed analysis and mitigation recommendations
A sophisticated malware campaign targeting WhatsApp users has been observed since February 2026. The attack chain begins with malicious Visual Basic Script files sent via WhatsApp messages, which, when executed, initiate a multi-stage infection process. The malware uses renamed Windows utilities, retrieves payloads from trusted cloud services, and installs malicious MSI packages. The campaign employs social engineering, stealth techniques, and cloud-based payload hosting to establish persistence and escalate privileges on victim systems. The attackers utilize legitimate tools and trusted platforms to reduce visibility and increase the likelihood of successful execution. The final stage involves the delivery of unsigned MSI installers that enable remote access to compromised systems. Join the discussion | AlienVault OTX General | 03/31/2026, 16:35:36 UTC Added: 03/31/2026, 18:38:16 UTC |
This analysis examines a multi-stage Windows malware campaign called SHADOW#REACTOR. The infection chain uses obfuscated VBS, PowerShell downloaders, and text-based payloads to deliver a Remcos RAT backdoor. Key features include fragmented text staging, .NET Reactor protection, reflective loading, and MSBuild abuse as a living-off-the-land binary. The campaign leverages complex obfuscation and in-memory execution to evade detection while establishing persistent remote access. Defensive recommendations focus on script execution monitoring, LOLBin abuse detection, and enhanced PowerShell logging to counter the sophisticated evasion techniques employed. Join the discussion | AlienVault OTX General | 01/13/2026, 16:17:00 UTC Added: 01/13/2026, 16:26:32 UTC |
The Water Saci campaign is a sophisticated malware operation targeting Portuguese-language systems, leveraging WhatsApp Web hijacking and multi-vector persistence mechanisms. It uses script-based techniques such as VBS downloaders and PowerShell scripts to automate malware distribution and maintain resilience. The campaign employs an email-based command and control infrastructure using IMAP for command retrieval, supplemented by HTTP polling for continuous communication. It features advanced anti-analysis capabilities and real-time remote control, enabling infected machines to operate as a coordinated botnet. The malware shares similarities with the Coyote banking trojan, indicating ties to Brazilian cybercriminal groups. Although no known exploits are reported in the wild, the campaign's complexity and persistence mechanisms pose a medium-level threat. European organizations with Portuguese-speaking user bases or connections to Brazil should be particularly vigilant. Mitigation requires targeted detection of script-based loaders, monitoring of WhatsApp Web session anomalies, and securing email clients against unauthorized IMAP access. Countries with strong economic or cultural ties to Brazil, such as Portugal and Spain, are most likely to be affected. Join the discussion | AlienVault OTX General | 10/27/2025, 15:20:48 UTC Added: 10/27/2025, 16:37:36 UTC |
A sophisticated spear-phishing campaign, likely linked to APT MuddyWater, is targeting CFOs and finance executives across multiple continents. The attackers use Firebase-hosted phishing pages with custom CAPTCHA challenges, malicious VBS scripts, and multi-stage payload delivery to deploy NetBird, a legitimate remote-access tool, for persistent system control. The campaign employs social engineering tactics, impersonating a Rothschild & Co recruiter to lure victims. Analysis revealed evolving infrastructure, updated payload paths, and overlaps with known MuddyWater activities. The attackers abuse legitimate tools like NetBird and AteraAgent for remote access and monitoring, while using sophisticated techniques such as AES encryption and math-based CAPTCHA lures to evade detection. Join the discussion | AlienVault OTX General | 08/21/2025, 07:35:40 UTC Added: 08/21/2025, 12:03:06 UTC |
A VBS-based infostealer called Cmimai Stealer has emerged, targeting Windows systems since June 2025. It collects system information, browser metadata, and screenshots, exfiltrating data via Discord webhooks. The malware uses PowerShell scripts for browser data collection and screen capture, running in a persistent loop every hour. It leverages WMI for system information gathering and employs JSON formatting for data exfiltration. While lacking advanced features like encrypted communication or credential theft, Cmimai Stealer serves as both an infostealer and a reconnaissance tool. Defensive considerations include monitoring high-risk process combinations, watching for specific PowerShell scripts and image files, and detecting Discord traffic with a unique User-Agent. Join the discussion | AlienVault OTX General | 08/13/2025, 11:57:19 UTC Added: 08/13/2025, 15:47:48 UTC |
A malicious Excel file using steganography was analyzed, revealing embedded XLS sheets and a complex infection chain. The file downloads an HTA file that creates a BAT file, which in turn generates and executes a VBS file. The VBS file fetches a VBA script that creates and runs a PowerShell script. The PowerShell script downloads an image containing a hidden payload delimited by specific tags. The payload is a Base64-encoded PE file, which is decoded and executed as a DLL. The final payload appears to be a Katz stealer. This analysis highlights the use of multiple file types and steganography techniques to evade detection. Join the discussion | AlienVault OTX General | 06/14/2025, 16:52:24 UTC Added: 06/16/2025, 15:04:28 UTC |
Showing 1 to 6 of 6 results