Close Menu
  • Home
  • Opinion
  • Region
    • Africa
    • Asia
    • Europe
    • Middle East
    • North America
    • Oceania
    • South America
  • AI & Machine Learning
  • Robotics & Automation
  • Space & Deep Tech
  • Web3 & Digital Economies
  • Climate & Sustainability Tech
  • Biotech & Future Health
  • Mobility & Smart Cities
  • Global Tech Pulse
  • Cybersecurity & Digital Rights
  • Future of Work & Education
  • Trend Radar & Startup Watch
  • Creator Economy & Culture
What's Hot

Nintendo providing low cost on Mario Galaxy 1+2 with Swap 2 buy

April 6, 2026

JIIF plans to speculate Rs 80-100 Cr in early-stage startups

April 6, 2026

PhotoGov Evaluate 2026: Do You Get a Authorities-Compliant Passport Photograph? – TechPluto

April 6, 2026
Facebook X (Twitter) Instagram LinkedIn RSS
NextTech NewsNextTech News
Facebook X (Twitter) Instagram LinkedIn RSS
  • Home
  • Africa
  • Asia
  • Europe
  • Middle East
  • North America
  • Oceania
  • South America
  • Opinion
Trending
  • Nintendo providing low cost on Mario Galaxy 1+2 with Swap 2 buy
  • JIIF plans to speculate Rs 80-100 Cr in early-stage startups
  • PhotoGov Evaluate 2026: Do You Get a Authorities-Compliant Passport Photograph? – TechPluto
  • From Knowledge to Alpha: An In-Depth Evaluation of JBStrategy’s AI-Pushed Quantitative Buying and selling
  • Anthropic acquires stealth startup Coefficient Bio in $400M deal
  • Smarter use of wooden may also help cool the planet, says new research
  • YouTube monetization replace: What creators have to know as ‘AI slop’ overwhelms the platform
  • SUPER73 Declares New Redesigned Electrical Bike Lineup
Monday, April 6
NextTech NewsNextTech News
Home - Cybersecurity & Digital Rights - Microsoft Warns of WhatsApp-Delivered VBS Malware Hijacking Home windows by way of UAC Bypass
Cybersecurity & Digital Rights

Microsoft Warns of WhatsApp-Delivered VBS Malware Hijacking Home windows by way of UAC Bypass

NextTechBy NextTechApril 6, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
Follow Us
Google News Flipboard
Microsoft Warns of WhatsApp-Delivered VBS Malware Hijacking Home windows by way of UAC Bypass
Share
Facebook Twitter LinkedIn Pinterest Email


Ravie LakshmananApr 01, 2026Social Engineering / Malware

Microsoft is asking consideration to a brand new marketing campaign that has leveraged WhatsApp messages to distribute malicious Visible Primary Script (VBS) recordsdata.

The exercise, starting in late February 2026, leverages these scripts to provoke a multi-stage an infection chain for establishing persistence and enabling distant entry. It is presently not recognized what lures the menace actors use to trick customers into executing the scripts.

“The marketing campaign depends on a mix of social engineering and living-off-the-land methods,” the Microsoft Defender Safety Analysis Workforce mentioned. “It makes use of renamed Home windows utilities to mix into regular system exercise, retrieves payloads from trusted cloud providers resembling AWS, Tencent Cloud, and Backblaze B2, and installs malicious Microsoft Installer (MSI) packages to keep up management of the system.”

The usage of reliable instruments and trusted platforms is a lethal mixture, because it permits menace actors to mix in regular community exercise and enhance the chance of success of their assaults.

The exercise begins with the attackers distributing malicious VBS recordsdata by way of WhatsApp messages that, when executed, create hidden folders in “C:ProgramData” and drop renamed variations of reliable Home windows utilities like “curl.exe” (renamed as “netapi.dll”) and “bitsadmin.exe” (renamed as “sc.exe”).

ms hacker

Upon gaining an preliminary foothold, the attackers goal to set up persistence and escalate privileges, finally putting in malicious MSI packages on sufferer programs. That is achieved by downloading auxiliary VBS recordsdata hosted on AWS S3, Tencent Cloud, and Backblaze B2 utilizing the renamed binaries.

“As soon as the secondary payloads are in place, the malware begins tampering with Consumer Account Management (UAC) settings to weaken system defenses,” Redmond mentioned. “It constantly makes an attempt to launch cmd.exe with elevated privileges, retrying till UAC elevation succeeds or the method is forcibly terminated, modifying registry entries underneath HKLMSoftwareMicrosoftWin, and embedding persistence mechanisms to make sure the an infection survives system reboots.”

These actions permit the menace actors to achieve elevated privileges with out consumer interplay by way of a mix of Registry manipulation with UAC bypass methods, and finally deploy unsigned MSI installers. This consists of reliable instruments like AnyDesk that present attackers with persistent distant entry, enabling the attackers to exfiltrate information or deploy extra malware.

“This marketing campaign demonstrates a complicated an infection chain combining social engineering (WhatsApp supply), stealth methods (renamed reliable instruments, hidden attributes), and cloud-based payload internet hosting,” Microsoft mentioned.

Elevate your perspective with NextTech Information, the place innovation meets perception.
Uncover the newest breakthroughs, get unique updates, and join with a worldwide community of future-focused thinkers.
Unlock tomorrow’s developments at the moment: learn extra, subscribe to our e-newsletter, and change into a part of the NextTech neighborhood at NextTech-news.com

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
NextTech
  • Website

Related Posts

LatAm’s Self-Taught Cyber Expertise Ignored Amid Cyberattack Glut

April 6, 2026

Fortinet Patches Actively Exploited CVE-2026-35616 in FortiClient EMS

April 5, 2026

Cisco Patches 9.8 CVSS IMC and SSM Flaws Permitting Distant System Compromise

April 5, 2026
Add A Comment
Leave A Reply Cancel Reply

Economy News

Nintendo providing low cost on Mario Galaxy 1+2 with Swap 2 buy

By NextTechApril 6, 2026

Nintendo is providing a reduction on the 2 Mario Galaxy video games with the acquisition of…

JIIF plans to speculate Rs 80-100 Cr in early-stage startups

April 6, 2026

PhotoGov Evaluate 2026: Do You Get a Authorities-Compliant Passport Photograph? – TechPluto

April 6, 2026
Top Trending

Nintendo providing low cost on Mario Galaxy 1+2 with Swap 2 buy

By NextTechApril 6, 2026

Nintendo is providing a reduction on the 2 Mario Galaxy video games with…

JIIF plans to speculate Rs 80-100 Cr in early-stage startups

By NextTechApril 6, 2026

Early-stage funding platform JITO Incubation and Innovation Basis (JIIF) plans to speculate…

PhotoGov Evaluate 2026: Do You Get a Authorities-Compliant Passport Photograph? – TechPluto

By NextTechApril 6, 2026

Having your passport photograph rejected was once only a nuisance. In 2026,…

Subscribe to News

Get the latest sports news from NewsSite about world, sports and politics.

NEXTTECH-LOGO
Facebook X (Twitter) Instagram YouTube

AI & Machine Learning

Robotics & Automation

Space & Deep Tech

Web3 & Digital Economies

Climate & Sustainability Tech

Biotech & Future Health

Mobility & Smart Cities

Global Tech Pulse

Cybersecurity & Digital Rights

Future of Work & Education

Creator Economy & Culture

Trend Radar & Startup Watch

News By Region

Africa

Asia

Europe

Middle East

North America

Oceania

South America

2025 © NextTech-News. All Rights Reserved
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms Of Service
  • Advertise With Us
  • Write For Us
  • Submit Article & Press Release

Type above and press Enter to search. Press Esc to cancel.

Subscribe For Latest Updates

Sign up to best of Tech news, informed analysis and opinions on what matters to you.

Invalid email address
 We respect your inbox and never send spam. You can unsubscribe from our newsletter at any time.     
Thanks for subscribing!