# WhatsApp Becomes Delivery Channel for ManageEngine RMM Malware in Multi-Country Campaign


A newly identified threat campaign is weaponizing WhatsApp to distribute malicious VBScript files that surreptitiously install ManageEngine's Remote Monitoring and Management (RMM) tool on target systems. Security researchers at Kaspersky have documented the active campaign targeting users across nine countries, exploiting the trust and ubiquity of WhatsApp as a social engineering vector to establish covert system access.


## The Threat


The campaign operates through a straightforward but effective social engineering chain: attackers send direct messages via WhatsApp Desktop and WhatsApp Web containing malicious VBScript attachments disguised as legitimate business documents. When users execute these scripts, the VBScript silently orchestrates the installation of ManageEngine RMM software—a legitimate administrative tool—without user consent or knowledge.


The geographic scope of the campaign is notable. Kaspersky has identified active targeting in:


  • Asia-Pacific: Malaysia, India, Singapore, Taiwan, Australia
  • Latin America: Brazil, Mexico
  • Europe: United Kingdom, Spain

  • The distribution across multiple continents and time zones suggests either a coordinated group with distributed infrastructure or multiple threat actors leveraging similar techniques.


    ## Background and Context


    ### Why ManageEngine RMM?


    ManageEngine Remote Monitoring and Management is a legitimate software platform developed by Zoho that allows IT administrators to remotely monitor, manage, and troubleshoot computers and servers across networks. In the hands of authorized users, it's a productivity tool. In the hands of attackers, it becomes a persistence mechanism.


    Once installed without authorization, ManageEngine RMM provides adversaries with:


  • Remote command execution on compromised machines
  • File transfer capabilities for exfiltrating data
  • System monitoring to observe user activity
  • Credential capture opportunities through keyboard logging
  • Lateral movement within corporate networks

  • The tool's legitimate nature is precisely what makes it dangerous in this context. It blends into normal system operations and may evade detection by security tools specifically tuned to flag malware rather than legitimate administrative utilities running in suspicious contexts.


    ### The VBScript Vector


    VBScript (Visual Basic Script) is a deprecated but still functional scripting language native to Windows systems. Its continued availability on Windows machines—particularly older enterprise systems—makes it an attractive option for attackers seeking low-friction code execution.


    The VBScript in this campaign serves as a loader—a small, efficient piece of code designed to:


    1. Download ManageEngine RMM software from attacker-controlled or compromised servers

    2. Execute the installation silently without prompting the user

    3. Configure ManageEngine to connect to attacker command-and-control infrastructure

    4. Remove traces of its own execution to avoid detection


    This approach allows attackers to avoid hosting massive malware binaries, instead leveraging the lightweight scripting capability that exists natively on nearly all Windows systems.


    ## The Social Engineering Play


    What makes this campaign particularly insidious is its reliance on WhatsApp, a platform most users associate with personal communication rather than security threats. The campaign likely uses:


  • Fake business context: Messages framed as invoices, reports, or contracts
  • Urgency messaging: Language implying time-sensitive business matters
  • Trusted-seeming attachments: File names matching expected business documents (.docx, .xlsx, .pdf with .vbs file extensions hidden)

  • WhatsApp's end-to-end encryption, ironically, creates a blind spot for traditional security monitoring. Messages sent via WhatsApp Web or Desktop aren't easily intercepted by corporate security gateways, and WhatsApp's terms of service prevent third-party security scanning of message contents.


    ## Attack Workflow


    The complete attack chain follows this sequence:


    | Stage | Action | Attacker Goal |

    |-------|--------|----------------|

    | 1. Social Engineering | Attacker sends WhatsApp message with malicious VBScript attachment | Establish contact and convince user to execute file |

    | 2. Execution | User downloads and executes .vbs file | Run attacker code with user privileges |

    | 3. RMM Installation | VBScript silently downloads and installs ManageEngine | Establish persistent remote access |

    | 4. Command & Control | ManageEngine connects to attacker infrastructure | Enable remote system manipulation |

    | 5. Exploitation | Attackers monitor system, harvest credentials, move laterally | Extract data or expand foothold |


    ## Technical Details


    ### VBScript Indicators


    Security teams should watch for:


  • VBScript files (.vbs) arriving via WhatsApp or other messaging platforms
  • File names attempting to impersonate business documents
  • Processes spawning ManageEngine installers from temporary directories
  • ManageEngine network connections to non-standard endpoints
  • Unsigned or improperly signed ManageEngine processes

  • ### ManageEngine Configuration


    Once installed, attackers typically configure ManageEngine to:


  • Connect to non-standard ports (not the default 8020-8022 range)
  • Use proxy chaining to obscure command-and-control traffic
  • Operate under legitimate Windows service names to avoid detection
  • Disable update notifications and security scanning

  • ## Implications for Organizations


    This campaign presents multifaceted risks across organizational security:


    ### Endpoint Compromise


    Successful exploitation grants attackers administrative-level access to compromised endpoints, enabling them to deploy additional malware, capture credentials, and establish persistence across reboots.


    ### Lateral Movement


    Once inside a corporate network, ManageEngine RMM becomes an internal reconnaissance tool. Attackers can map network topology, identify sensitive systems, and move laterally to servers and databases.


    ### Data Exfiltration


    Access to user workstations—particularly those of administrative staff, finance, or executive personnel—enables credential theft, document exfiltration, and business intelligence gathering.


    ### Supply Chain Risk


    If targeted organizations include software vendors or managed service providers, compromised systems could be repurposed to target their clients, creating cascading compromise scenarios.


    ## Recommendations


    ### For Individual Users


  • Verify unexpected attachments: If you receive a file via WhatsApp from an unknown sender or an unexpected message from a known contact, verify through an alternative communication channel before opening
  • Be cautious with scripts: VBScript files (.vbs, .vbe, .js, .jse, .wsf) should never be executed unless you explicitly created them or downloaded them from a trusted, verified source
  • Use security software: Ensure endpoint protection is active and scanning inbound files
  • Keep systems patched: Regularly update Windows and all installed software

  • ### For Organizations


  • Email and messaging security: Deploy advanced threat detection on both email and web-based messaging platforms where feasible. Consider restricting VBScript execution via Group Policy on Windows systems that don't require it
  • User awareness training: Include messaging app security in security awareness programs, emphasizing that social engineering attacks are not limited to email
  • Endpoint Detection and Response (EDR): Deploy EDR solutions that can detect suspicious process execution chains, particularly scripts spawning installers or administrative tools
  • Network segmentation: Limit lateral movement by segregating sensitive systems and implementing zero-trust network access controls
  • Inventory administrative tools: Maintain a whitelist of approved RMM and administrative tools. Flag unauthorized installations of ManageEngine or similar software
  • Disable unnecessary scripting: Where business requirements allow, disable VBScript execution via Group Policy or AppLocker policies
  • Monitor and log: Enable PowerShell logging and monitor for VBScript execution patterns, particularly those originating from %TEMP% or %AppData% directories

  • ## Hunter's Checklist


    Security teams investigating potential compromise should:


  • Search logs for cscript.exe or wscript.exe execution, particularly with .vbs file arguments
  • Hunt for ManageEngine installation files in non-standard directories
  • Review network traffic from endpoints to non-standard ports targeting external IP addresses
  • Query Windows Event Logs for service installation events matching ManageEngine identifiers
  • Examine WhatsApp Web/Desktop logs for recently accessed files

  • ---


    ## HackWire Analysis


    This campaign represents a convergence of escalating trends in threat actor tactics: the shift toward messaging platforms as attack vectors, the weaponization of legitimate administrative tools, and the continued effectiveness of social engineering at scale.


    What's particularly notable is *why this works now*. WhatsApp has become ubiquitous in business communication—many users reflexively trust content arriving through it because it carries the implicit endorsement of personal contacts or ostensible business peers. Unlike email, where security awareness has been institutionalized for years, messaging app security remains a blind spot for most organizations. Users accept files through WhatsApp with less scrutiny than they would through corporate email.


    The choice of ManageEngine RMM is tactically brilliant. It's not exotic malware requiring custom development; it's a legitimate tool that will execute without triggering behavioral anomalies, evade signature-based detection, and blend seamlessly into legitimate administrative traffic. This is the evolution of living-off-the-land attacks—not just using native OS capabilities, but quietly deploying legitimate software as a persistence mechanism.


    The geographic distribution suggests either organized targeting of specific industries or a more general opportunistic campaign relying on social engineering effectiveness across regions. Either way, the multi-country scope indicates this isn't a localized problem—it's a template that works, and other threat actors will adopt it.


    For defenders, the critical lesson is this: the perimeter has dissolved. Security can't rely on email gateways filtering malicious content when attackers are bypassing them entirely via consumer messaging platforms. The answer isn't to lock down WhatsApp (that's not realistic), but to shift to detection-based defenses at the endpoint and network level—catching ManageEngine installations, VBScript executions, and suspicious administrative tool configurations as they happen, not trying to prevent them at the gateway.


    — *HackWire Editorial*


    ---


    ## Related Coverage


  • Read more in our [Tools](https://www.hackwire.news/category/tools) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)