Threats Tagged 'vbscript'
View all threats tagged with 'vbscript'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'vbscript'
Click on any threat for detailed analysis and mitigation recommendations
An active malware campaign has been discovered distributing malicious VBScript files through WhatsApp direct messages since June 2026. The operation affects users across multiple countries, with Malaysia experiencing the highest concentration of victims. Attackers compromise WhatsApp accounts and send weaponized VBS files disguised as business and financial documents to contacts. The multi-stage infection chain ultimately deploys legitimate ManageEngine Endpoint Central RMM software, providing persistent remote access to compromised systems. The scripts employ heavy obfuscation, Chinese-language comments, and modify Windows UAC settings. Infrastructure overlaps with ValleyRAT and Gh0st RAT operations suggest possible Chinese-speaking operators, though attribution remains uncertain. The campaign primarily targets individual users through opportunistic rather than focused methods, exploiting social engineering techniques with localized filenames in multiple languages. Join the discussion | AlienVault OTX General | 06/22/2026, 11:01:01 UTC Added: 06/22/2026, 20:24:23 UTC |
This analysis examines Gamaredon's (UAC-0010, Armagedon) advanced espionage operations targeting Ukrainian government, military, and critical infrastructure. The FSB-operated group deploys GammaSteel, a sophisticated stealer operating almost entirely from memory using Windows DPAPI encryption and storing 71 distinct payload functions in the HKCU\Printers registry key. The malware employs three concurrent data acquisition mechanisms: timed drive scans, USB monitoring for air-gapped systems, and real-time file surveillance. Exfiltration occurs via legitimate S3-compatible cloud storage (Tebi.io) with fallback to operator-controlled servers. The infection chain extensively uses VBScript for evasion, Dead Drop Resolvers on platforms like Telegram and Mastodon for C2 configuration, and includes bidirectional backdoor capabilities enabling arbitrary remote code execution. Infrastructure demonstrates high automation with servers rotated approximately every 24 hours. Join the discussion | AlienVault OTX General | 06/04/2026, 13:57:26 UTC Added: 06/05/2026, 08:49:15 UTC |
Operation MacroMaze, attributed to APT28 (Fancy Bear), targets entities in Western and Central Europe from September 2025 to January 2026. The campaign utilizes basic tools and legitimate services for infrastructure and data exfiltration. Multiple documents with varying macro variants act as droppers, establishing a foothold by creating files in the %USERPROFILE% folder. The attack chain involves VBScript execution, scheduled task creation for persistence, and a multi-stage process using batch files. Exfiltration is achieved through HTML-based techniques, leveraging webhook.site for data transmission. Despite its simplicity, the campaign demonstrates effective operational tradeoffs, making detection and attribution challenging. Join the discussion | AlienVault OTX General | 02/16/2026, 14:28:58 UTC Added: 02/17/2026, 16:15:34 UTC |
Tangerine Turkey is a cryptomining campaign that propagates via VBScript worms spread through USB drives, leveraging legitimate system binaries for execution and persistence. The malware employs advanced defense evasion techniques such as registry modification and masquerading malicious files as legitimate system components. It establishes persistence through malicious services and scheduled tasks while attempting to disable Windows Defender. Although its primary objective is unauthorized cryptocurrency mining, its capabilities for persistence and lateral movement pose broader security risks. The campaign uses living-off-the-land binaries and creates mock directories to conceal its activities. No known CVEs or exploits are currently associated with this threat. The medium severity rating reflects the financial motivation and potential for system compromise without immediate destructive impact. European organizations using Windows systems with USB access are at risk, especially those with lax endpoint security controls and high-value targets. Mitigation requires targeted controls beyond generic advice, including USB device management, monitoring for living-off-the-land abuse, and registry integrity checks. Join the discussion | AlienVault OTX General | 10/29/2025, 18:37:29 UTC Added: 10/29/2025, 20:13:19 UTC |
APT-C-53, also known as Gamaredon, is a Russian state-sponsored threat group active since 2013, targeting Ukrainian government and military entities. The group has upgraded its attack techniques, focusing on dynamic cloud-based C2 infrastructure and targeted delivery of cloud storage tools. In 2025, they conducted high-density intelligence theft activities against Ukrainian government agencies. The attack chain involves dynamic changes in infrastructure, abuse of Microsoft Dev Tunnels, and sophisticated data exfiltration techniques. The group employs white-listed domain camouflage, domain shadowing, and weaponization of cloud tunnel services to evade detection. Their data theft process includes registry-based persistence, multi-stage payload delivery via Cloudflare Workers, and exfiltration through legitimate cloud tools like Dropbox. Join the discussion | AlienVault OTX General | 09/01/2025, 09:55:21 UTC Added: 09/01/2025, 10:17:38 UTC |
A sophisticated variant of the Masslogger credential stealer malware has been identified spreading through .VBE files. This multi-stage fileless malware heavily relies on Windows Registry to store and execute its malicious payload. The infection begins with a .VBE file, likely distributed via spam email or drive-by downloads. The malware sets up registry keys for storing commands, stager configurations, and the final payload. It establishes persistence through a scheduled task and uses techniques to simulate user input. The malware employs multiple stagers to decode and load the final Masslogger payload, which is injected into the AddInProcess32.exe process. The payload targets multiple web browsers and email clients to steal credentials and sensitive information, with capabilities including keylogging, screen capture, and data exfiltration via FTP, SMTP, or Telegram. Join the discussion | AlienVault OTX General | 06/18/2025, 17:19:13 UTC Added: 06/18/2025, 19:46:49 UTC |
A highly focused malicious campaign targeting Portuguese organizations, particularly in government, finance, and transportation sectors, has been uncovered. The campaign is linked to Lampion malware, an infostealer focusing on banking information. The threat actors have incorporated ClickFix lures, a social engineering technique that tricks victims into executing malicious commands. The infection chain involves multiple stages of obfuscated Visual Basic scripts, evasion techniques, and a complex execution method. While the final payload was not delivered in this instance, the campaign demonstrates the threat actors' adaptation and sophistication. The article emphasizes the importance of enhanced detection capabilities and provides recommendations for security practitioners to address this evolving threat. Join the discussion | AlienVault OTX General | 05/06/2025, 10:59:06 UTC Added: 06/05/2025, 10:14:15 UTC |
Showing 1 to 7 of 7 results