Tuesday 22 September 2026 04:14:26 GMT+02:00

Netcrook

HomeManifesto
News
Techcrook
Geocrook
WikicrookTeamAppContact
EnglishItaliano

#VBScript


When a Script Comment Becomes a Trap for AI Security Tools

Published: 11 September 2026 12:06Category: AI Security & Agentic SystemsGeo: Europe / UkraineAuthor: INTEGRITYFOX

A VBScript sample tied to GuardBreaker shows how untrusted text inside code comments can be used to confuse AI-assisted malware analysis without changing how the script runs.

The Trusted Remote Tool That Turned Into a Script Factory

Published: 07 September 2026 16:46Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: PATCHKNIGHT

Three related incidents show how a legitimate remote-support stack can be bent into a staged malware path, with VBScript used to reach newly connected hosts.

When Help Turns Hostile: Windows Remote-Access Tools Used as a Persistence Route

Published: 03 September 2026 12:04Category: Malware & BotnetsGeo: North America / USAAuthor: SIGNALMONK

A late-August cluster of intrusions shows how trusted support software can be repurposed into a quiet backdoor path on Windows endpoints.

GitHub, Scripts, and a Trusted Windows Utility Form a Quiet Malware Conveyor Belt

Published: 31 August 2026 10:35Category: Malware & BotnetsGeo: South America / ColombiaAuthor: IRONQUERY

A reported loader chain tied to Blind Eagle combines public code hosting, VBScript, PowerShell, and InstallUtil to place AsyncRAT on Windows systems.

The Worm That Turned Email Into a Weapon

Published: 05 August 2026 17:16Category: Malware & BotnetsGeo: Asia / PhilippinesAuthor: SIGNALMONK

ILOVEYOU remains a reminder that one attachment, one script, and one trusted inbox can still be enough to trigger a mass outbreak.

Inside the Lampion Lure: A Malware Chain Built to Look Ordinary

Published: 24 July 2026 10:39Category: Malware & BotnetsGeo: Europe / PortugalAuthor: IRONQUERY

A Portuguese phishing run shows how attackers can hide a serious payload behind routine mail, layered scripts, and a trusted Windows launcher.

When a RAR File Becomes a Delivery System for Windows Persistence

Published: 24 June 2026 10:20Category: Malware & BotnetsGeo: Europe / UkraineAuthor: SIGNALMONK

A targeted campaign tied to Ukraine’s UAV ecosystem shows how a booby-trapped archive, a script loader, and a decoy document can turn routine file handling into a foothold.

WhatsApp Messages Are Being Used to Smuggle Scripts, Not Just Spam

Published: 23 June 2026 10:46Category: Security Awareness & Social EngineeringGeo: Asia / IndiaAuthor: NEURALSHIELD

A malicious VBScript lure dressed up as a document shows how trusted chat channels can carry administrative tools into the wrong hands.

When a Chat Message Becomes a Windows Script Trap

Published: 23 June 2026 02:07Category: Security Awareness & Social EngineeringAuthor: PATCHKNIGHT

An ongoing WhatsApp lure uses fake business documents and VBScript files, showing how a trusted messenger can become the first step in a PC compromise.

Trusted Chat, Untrusted Payload: How WhatsApp Messages Became a Windows Delivery Route

Published: 22 June 2026 18:22Category: Malware & BotnetsGeo: North America / USAAuthor: NEXUSGUARDIAN

Compromised WhatsApp accounts are being used to push malicious VBScript files, then legitimate RMM tools are abused to keep access alive on infected Windows machines.

A Lookalike npm Name, Then a Windows Script Chain: The Supply-Chain Trap Behind a RAT Drop

Published: 22 June 2026 14:52Category: Malware & BotnetsGeo: North America / USAAuthor: IRONQUERY

A typosquatted package in the npm ecosystem shows how a single confusing name can hand attackers a path from dependency install to Windows-native execution.