WhatsApp DMs Push VBScript Loaders That Deploy Legitimate RMM Tools

An active campaign abuses WhatsApp Desktop and Web to distribute scripted droppers that install commercial remote-management software across at least ten jurisdictions.

ThreatVectr Newsdesk· 2 min read
WhatsApp DMs Push VBScript Loaders That Deploy Legitimate RMM Tools
Share

A campaign documented by researchers at Kaspersky is using direct messages on WhatsApp to deliver Visual Basic Script files that, once executed, sideload commercial Remote Monitoring and Management software onto victim endpoints.

The targeting is broad. Affected users have been observed in Malaysia, Brazil, India, Mexico, Singapore, the United Kingdom, Spain, Taiwan and Australia, across both WhatsApp Desktop and the browser-based WhatsApp Web client.

The technique is notable less for novelty than for what it implies about disclosure and enforcement gaps around dual-use software.

RMM tools are not malware. They are licensed products sold to managed service providers and IT departments. When an attacker installs one on a victim's machine, the binary itself is signed, the network traffic looks routine, and most endpoint controls treat the activity as benign. That dynamic has drawn regulator attention before. CISA, the NSA and MS-ISAC flagged the pattern in a joint advisory on malicious use of RMM software issued in January 2023, which remains the operative federal guidance on the threat class.

The delivery vector here is the messaging surface itself. WhatsApp messages are end-to-end encrypted, which means upstream network inspection by an enterprise gateway will not see the attachment in transit. Detection has to happen on the endpoint, after the VBScript executes.

That raises a policy question Threat Vectr has been tracking. Under the SEC's final cybersecurity disclosure rule at 17 CFR §229.106, registrants must disclose material cyber incidents on Form 8-K Item 1.05 within four business days of a materiality determination. A confirmed RMM-based intrusion that began with a WhatsApp-delivered script would, depending on scope, plausibly meet that threshold. The rule has been in effect since December 18, 2023, and the SEC has not narrowed its application based on initial-access method.

For EU-regulated entities, the analogous trigger sits in NIS2 Article 23, which requires an early warning to the relevant CSIRT within 24 hours of awareness of a significant incident. Member-state transposition remains uneven, but the obligation is live in jurisdictions that have completed implementation.

Meta has not, at the time of writing, published a security advisory tied to this specific abuse pattern. WhatsApp's general guidance continues to direct users to its in-app reporting flow.

Mitigation is unglamorous. Block or alert on unsigned VBScript execution from user profile directories. Inventory installed RMM agents and flag any that are not on an approved list. Treat unsolicited file attachments over consumer messaging apps as untrusted by default, including on managed devices where WhatsApp Desktop is permitted.

The campaign is ongoing.

© 2026 Threat Vectr