Threats Tagged 'vbscript loader'
View all threats tagged with 'vbscript loader'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'vbscript loader'
Click on any threat for detailed analysis and mitigation recommendations
Multiple organizations experienced attacks beginning with social engineering that led to rogue ScreenConnect installations executing suspicious VBScript files. The attack chain involved four sequential VBScript payloads (1.vbs through 4.vbs) used to profile systems, check for security products, establish persistence, and deploy additional tools. Modified ScreenConnect clients enabled worm-like propagation by automatically transferring and executing these scripts on newly connected endpoints. The attacks included deployment of additional RMM tools like UltraViewer, cryptocurrency miners, and tunneling utilities. Systems were profiled based on installed security products, RAM capacity, and existing ScreenConnect installations. Persistence was achieved through Windows Registry Run Keys and concealed services. The campaign demonstrated sophisticated evasion techniques including AMSI bypass attempts, Windows Defender exclusions, and UAC bypass mechanisms. Join the discussion | AlienVault OTX General | 09/03/2026, 08:17:05 UTC Added: 09/03/2026, 12:53:01 UTC |
In February 2026, an attack chain was discovered that utilized a fraudulent Adobe Acrobat Reader download page to deceive victims into installing ConnectWise's ScreenConnect, a legitimate remote access tool exploited for malicious purposes. The attack employs sophisticated evasion techniques including heavy obfuscation, .NET reflection for in-memory payload execution, and dynamic code construction. A VBScript loader initiates the chain by downloading and executing obfuscated PowerShell commands that compile C# code entirely in memory. The loader manipulates the Process Environment Block to masquerade as legitimate Windows processes and abuses auto-elevated COM objects to bypass User Account Control without user prompts. This multi-layered approach successfully evades signature-based defenses and hinders forensic analysis while ultimately deploying ScreenConnect for unauthorized remote access. Join the discussion | AlienVault OTX General | 04/10/2026, 08:15:00 UTC Added: 04/10/2026, 10:20:47 UTC |
Showing 1 to 2 of 2 results