Last seven days
- First activity
- Jul 23, 2026
- Last activity
- Jul 28, 2026
- Feed role
- C2
- Host form
- 3 IP / 31 hostnames
Vjw0rm is a commodity JavaScript remote access trojan (RAT) first seen around 2016 and originally associated with an author known as "v-j." It uses Windows Script Host components including WScript.Shell, ActiveXObject, and MSScriptControl for execution and dynamic scripting.
Profile source: Mallory opens in a new tabVjw0rm
Vjw0rm is a commodity JavaScript remote access trojan (RAT) first seen around 2016 and originally associated with an author known as "v-j." It uses Windows Script Host components including WScript.Shell, ActiveXObject, and MSScriptControl for execution and dynamic scripting. Documented capabilities include command execution, file operations, registry operations, environment reconnaissance, WMI-based security product enumeration, and self-propagation to USB or network locations. Reporting cited in the content also notes that malware used in TA2541 campaigns, including vjw0rm, supports information gathering and remote control of infected machines.
The malware has been observed in phishing-driven intrusion chains associated with TA2541, a financially motivated cybercriminal actor active since at least 2017. TA2541 has targeted aviation, aerospace, transportation, manufacturing, and defense organizations, typically using aviation-, transportation-, and travel-themed lures delivered via high-volume email campaigns. In these campaigns, vjw0rm has been delivered through chains involving obfuscated VBS files, PowerShell, cloud-hosted payloads, and persistence via scheduled tasks and Windows Registry Run keys. Proofpoint specifically observed recent vjw0rm campaigns leveraging task creation and registry persistence.
A separate 2026 campaign described in the content used a WinRAR self-extracting archive disguised as a software keygen to deploy Vjw0rm through a four-layer dropper chain. The outer archive silently executed a decoy KeyGen.exe and a nested Patch.exe SFX archive. Patch.exe dropped setup.exe, a compiled AutoHotkey orchestrator, along with approximately 200 legitimate Windows troubleshooting pack files used as camouflage. The orchestrator staged payloads under C:\ProgramData\Adobe\AIR\Logs\gp\PerfLogs\Google\start\ and C:\Users\Public\Settings\A\News\, then launched win.ps1, Script.js, Patch.js, and a renamed WindowsUpdater.js in parallel. win.ps1 and Script.js both retrieved content from hxxps://upaste[.]me/r/8dc960578b490d703, which functioned as a dead-drop resolver. Script.js established persistence by copying itself to %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\Script.js, while Patch.js created scheduled tasks and used Unicode fullwidth character obfuscation. The final RAT core was embedded locally as PCWDiagnostic.xml (SHA256 33629caa9918c81a5e1ce58c1682e7465ac6f4bccd8d9c13d429249920c6d557), renamed to WindowsUpdater.js, and executed as Vjw0rm. Additional artifacts from this campaign include outer SFX SHA256 64a92d23f6efcc17cdd3016a52e0503a13350f037785220a08b74b46333a3eee, nested Patch.exe SHA256 4a341185e5e0983feca8a39b65b92a6d69b72d2093aa1a1b134b39d63a1c9a96, setup.exe SHA256 0419d91f867968fce085b3a1bbe3c3dc96e1b83e8e8c27d4a5d4e64be1389dcc, and GUID 34892937-8948-47dc-9c73-e8f5c918f49a in Patch.js. Turkish-language artifacts in the SFX comment suggested a likely Turkish-speaking commodity cybercrime operator.
The content also notes that Vjw0rm has appeared in broader commodity malware delivery ecosystems beyond TA2541, including campaigns documented by Proofpoint and Positive Technologies and activity associated with the RevengeHotels/TA558 cluster, where it was one of several RATs delivered in campaigns targeting hospitality and travel-related victims.
C2 tracking
Derp observations, rolling seven-day window
Samples
98596cb2660036dfdac7d3faf3dd054ae35a9fdf8d567e31629c6a9ffb6073f6 a3114a38ba8e4690900eedbdbe6cf914708428015491e00dc33c991ad2305377 0f63575601b324548192347de46b35fca6a9b2259f5aa1fc75c8d340a009d54b 10355041febbbc052feeeb31c789a010df6ada74adadf3459db4be3e127b6064 3bc3448d0f2247595195bb8a6adf75d4c5a1b5a447b5bd837d10ba56005fbe00 59e81942f83d6c91c129e98f366746c924743eec29eacaa57832a5e4bbe64f16 9d400fc841795af228ac4a3953b20cd007ddaa1158b869294a9119abaca46df5 77f1f6861f989706ebc16fde9e043954c3b23a634ba6bfa0fde5afda054b571b 7a2e35f54e8f9841107d7d94b17b0b7ac1b66b64a48e7d7d26f1d83a82dfe7b0 8907533466ea5190a398b39fad88016c8b359b2097628ee81475f2b5dae504f3 Reported operators
In recent campaigns, vjw0rm and STRRAT also leveraged task creation and adding entries to the registry.
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.