Picture the alert that never fired. A WhatsApp message lands, someone opens an attachment, a VBScript runs, and a few stages later a remote monitoring and management agent is quietly installed on the box. Not a bespoke trojan. A commercial RMM product, the same category of tool your own IT team uses to push patches and fix printers. Kaspersky’s researchers traced exactly this campaign, and it’s a cybersecurity story that should bother you more than the average RAT writeup, because there’s nothing to detonate. The attacker didn’t sneak past your defenses. They walked through the front door carrying software you’d happily approve.
That’s the uncomfortable thread running through this week’s news. The smartest attackers have largely stopped trying to look like malware. They’re investing in looking legitimate instead.

The malware came with a license agreement
Here’s what makes RMM abuse so effective. Remote monitoring and management agents are designed to do everything an attacker wants: run commands, transfer files, maintain persistence, and survive reboots, all over an encrypted channel to a cloud console. They’re code-signed. They’re sold with support contracts. Half of them are probably already whitelisted somewhere in your environment because a managed service provider asked you to allow them three years ago.
So when a multi-stage VBScript chain drops one of these agents, your endpoint protection has a genuinely hard problem. The binary isn’t malicious. The behavior, viewed in isolation, looks like sanctioned IT work. Your threat detection rules are tuned to spot the unusual and the unsigned, and this is neither.
The delivery is the only sketchy part, and it arrives through WhatsApp, a channel most security stacks don’t inspect at all.
Legitimacy is the actual payload now
The RMM trick isn’t an outlier. Look at the malicious npm packages caught posing as PostCSS tooling, with names like postcss-minify-selector and postcss-minify-selector-parser. They’re built to be mistaken for real, widely used build dependencies, and they deliver a Windows RAT to anyone who installs them. The name is the disguise. A developer scanning a package list sees something that looks like the ecosystem they already trust and pulls it straight into a build pipeline that runs with real privileges.
Then there’s the crypto heist Dark Reading covered, where attackers built an entire fake reputation across GitHub, YouTube, and even VirusTotal to make a clipboard hijacker look credible before anyone ran it. They didn’t defeat your scanners. They populated the exact signals you use to decide what’s safe.
See the pattern? Three different campaigns, one strategy. Don’t evade the trust system. Feed it.
For years we trained detection around a simple idea: bad things look bad. Unsigned binaries, weird process trees, known-malicious hashes. That model still catches plenty. It also creates a blind spot you can drive a managed service agent through, because a signed RMM tool, a familiarly named package, and a GitHub repo with stars all read as “good” to a control that grades software by its pedigree.

What your stack is actually missing
You can’t buy a product that solves “the thing was legitimate.” You close this gap by changing what you watch and how you decide. Reputation is an input, not a verdict.
Start with the moves you can make this week:
- Inventory every RMM tool in your environment and define the legitimate set. If you sanction one vendor’s agent, every other RMM binary becomes an immediate, high-confidence alert. Unexpected RMM installs are one of the cleanest detections you can build.
- Alert on the install moment, not just the behavior. A new remote-management service appearing on an endpoint that never had one is the event worth catching. After the agent is running, it blends in.
- Inspect the channels you’ve been ignoring. WhatsApp, personal webmail, and messaging apps deliver payloads your mail gateway and firewall never see. Decide whether they belong on corporate devices at all, and apply application control to script interpreters like
wscriptandcscript. - Treat dependencies as untrusted until verified. Pin versions, use a vetted internal registry, and check package names against typosquats before they reach a build host. A name that looks familiar is not provenance.
- Stop trusting VirusTotal scores and star counts as proof. Reputation is now something attackers manufacture. Verify maintainers, publish dates, and download history before you lean on a number.
The longer game is structural. Defense in depth means assuming the signed binary and the trusted package will both get through eventually, so application allowlisting, network egress controls that flag agents phoning home to unknown consoles, and least privilege all have to hold even when the front-line verdict says “fine.” Security hardening of your build and deployment pipelines matters as much as endpoint threat-protection here, because that’s where a poisoned dependency does its real damage.
And keep the boring controls sharp. Brute-force protection on every exposed login, rate limiting, and monitored authentication endpoints still close off the noisy paths attackers use when the quiet one fails. Your incident response plan needs a specific branch for “the malicious software was legitimate,” because the containment steps differ. You’re not just killing a process. You’re revoking a tool, rotating credentials it could reach, and figuring out who approved it and when.
This is a cybersecurity problem you can’t buy your way out of
The vendors will tell you their next box catches this. Be skeptical. The whole point of these campaigns is that the artifacts look clean to any tool grading software by where it came from. A cyber security program that leans entirely on reputation, signatures, and known-bad lists is grading on a curve the attacker controls.
What actually works is cheaper and more annoying: decide in advance what belongs in your environment, alert hard when something outside that set shows up, and verify trust instead of inheriting it. The RMM agent, the PostCSS lookalike, and the reputation-laundered clipper all count on you taking legitimacy at face value. Stop doing that, and most of this strategy falls apart.
Your allowlist isn’t a guest list. Treat it like one and the attackers will keep RSVPing.
Sources
- A VBScript campaign distributed through WhatsApp deploying RMM software
- Malicious npm Packages Pose as PostCSS Tools to Deliver Windows RAT
- Crypto Heist Fueled by Elaborate Fake Reputation-Boosting Campaign
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
