A VBScript sample tied to GuardBreaker shows how untrusted text inside code comments can be used to confuse AI-assisted malware analysis without changing how the script runs.
Three related incidents show how a legitimate remote-support stack can be bent into a staged malware path, with VBScript used to reach newly connected hosts.
A late-August cluster of intrusions shows how trusted support software can be repurposed into a quiet backdoor path on Windows endpoints.
A reported loader chain tied to Blind Eagle combines public code hosting, VBScript, PowerShell, and InstallUtil to place AsyncRAT on Windows systems.
ILOVEYOU remains a reminder that one attachment, one script, and one trusted inbox can still be enough to trigger a mass outbreak.
A Portuguese phishing run shows how attackers can hide a serious payload behind routine mail, layered scripts, and a trusted Windows launcher.
A targeted campaign tied to Ukraine’s UAV ecosystem shows how a booby-trapped archive, a script loader, and a decoy document can turn routine file handling into a foothold.
A malicious VBScript lure dressed up as a document shows how trusted chat channels can carry administrative tools into the wrong hands.
An ongoing WhatsApp lure uses fake business documents and VBScript files, showing how a trusted messenger can become the first step in a PC compromise.
Compromised WhatsApp accounts are being used to push malicious VBScript files, then legitimate RMM tools are abused to keep access alive on infected Windows machines.
A typosquatted package in the npm ecosystem shows how a single confusing name can hand attackers a path from dependency install to Windows-native execution.