WhatsApp DMs Push VBScript Loaders That Deploy Legitimate RMM Tools
An active campaign abuses WhatsApp Desktop and Web to distribute scripted droppers that install commercial remote-management software across at least nine jurisdictions.

Key points
- Kaspersky has documented an active campaign delivering malicious VBScript files via WhatsApp direct messages.
- Victims span WhatsApp Desktop and WhatsApp Web users across Malaysia, Brazil, India, Mexico, Singapore, the United Kingdom, Spain, Taiwan, and Australia.
- The payload is legitimate Remote Monitoring and Management software, meaning endpoint controls and network inspection often treat it as benign.
- WhatsApp's end-to-end encryption blocks upstream gateway inspection, so detection must happen on the endpoint after the script executes.
- Organisations covered by SEC cybersecurity disclosure rules or EU NIS2 obligations may face reporting duties if an intrusion of this type is confirmed material.
What makes this campaign different from ordinary malware delivery?
It isn't delivering malware, strictly speaking. The VBScript files Kaspersky documented are droppers: they execute, install a commercial RMM agent, and leave behind a signed binary doing licensed work. Most endpoint controls and network monitors treat that activity as routine. CISA and the NSA flagged this exact dynamic in a joint advisory on malicious RMM use in January 2023, and it remains the operative federal guidance. The threat class isn't new, but the delivery surface is worth attention. We've tracked RMM abuse across five stories since first covering it on 23 June 2026, and the consistent thread is how well legitimacy serves as a shield.
Should you worry about the WhatsApp delivery vector?
Yes, for a specific reason. WhatsApp messages are end-to-end encrypted, so an enterprise gateway won't see the attachment in transit. There's no inspection window upstream. By the time a defender has anything to look at, the script has already run. That's a meaningful gap for organisations that permit WhatsApp Desktop on managed endpoints, and our 8 June 2026 story on Meta catching NSO spear-phishing on WhatsApp is a reminder that the platform has been a target surface for some time.
What are the disclosure obligations if an organisation is hit?
The SEC's cybersecurity disclosure rule requires registrants to report material cyber incidents on Form 8-K within four business days of a materiality determination. An RMM-based intrusion that began via a WhatsApp-delivered script could plausibly meet that threshold depending on scope. The SEC hasn't narrowed application of the rule by initial-access method. For EU-regulated entities, NIS2 requires an early warning to the relevant national computer security incident response team once an organisation becomes aware of a significant incident; member-state transposition remains uneven, but the obligation is live where implementation is complete. Meta hasn't published a security advisory tied to this specific abuse pattern.
What should security teams do right now?
Mitigation isn't complicated, but it is unglamorous. Block or alert on unsigned VBScript execution from user profile directories. Inventory every installed RMM agent and flag anything not on an approved list. Treat unsolicited file attachments over consumer messaging apps as untrusted by default, even on managed devices where WhatsApp Desktop is explicitly permitted. The campaign is ongoing.



