Last seven days
- First activity
- Aug 3, 2026
- Last activity
- Aug 6, 2026
- Feed role
- C2
- Host form
- 0 IP / 30 hostnames
Vjw0rm is a commodity Windows remote access trojan implemented in JavaScript and commonly executed through Windows Script Host.
Profile source: Mallory opens in a new tabVjw0rm
Vjw0rm is a commodity Windows remote access trojan implemented in JavaScript and commonly executed through Windows Script Host. Active since at least 2016, it is associated with broad cybercriminal distribution rather than a single exclusive operator. The malware provides remote control and information-gathering capabilities on infected systems, including command execution, file and registry operations, environment reconnaissance, and security-product enumeration via WMI. Reported variants and campaigns have also supported self-propagation to USB and network locations.
Vjw0rm has been delivered through multiple social-engineering and malware-staging chains. Documented delivery methods include phishing campaigns, including judicial-notification lures and broader travel-, aviation-, and transportation-themed email operations, as well as cracked-software or keygen lures packaged in multi-stage archive-based droppers. In observed Windows infections, Vjw0rm has been launched through layered script execution involving PowerShell, JScript/VBScript hybrids, AutoHotkey-based orchestration, and dead-drop style retrieval from paste services.
Persistence mechanisms observed in Vjw0rm-related campaigns include startup-folder script placement, scheduled tasks, and Windows registry Run-key style persistence. The malware has been linked to campaigns attributed to TA2541, a financially motivated cybercriminal actor known for targeting aviation, aerospace, transportation, manufacturing, and defense organizations with commodity RATs. Vjw0rm has also appeared in broader commodity malware ecosystems used against other sectors through phishing and lure-based delivery. Its continued use reflects the durability of script-based RATs that combine low development cost, flexible staging chains, and effective post-compromise remote administration on Windows hosts.
C2 tracking
Derp observations, rolling seven-day window
Samples
3809c5b99a5da43070b1fa70b77756c72cc3b5cc1996edd080f078a9010d9784 5a5cea86bff58e1762233f808e7ba0645a460dac8c4d855c1b764430876f8785 9e4e61c64da1c3511abedadf200889aff63236aa88efb0d18077a17d076caeb9 c6186f60c2e75e21820d8d7297aff52f3f3d45d3dac18bf11873cc3dcf0c6dad 99ebda03950dec5b23b978df6d6d6cf254bd6781ed5d23b8ad8dfe3c230a9515 187979252bdf6e932753613b86202ce215132ccca8236215321c5c67b1de7875 3e68725df6872b5201f2462426b7b1b41aa8b3d7c1525b5be89f7e9d4032aac6 47ccf7af5db91cfd6774898fe25950ec95ac5a9cc44334603259b2c10bca7b8a cfecc2bc043b4b5e3d412bea8664227cb437b0deb1e75657a933e38492a8a1c8 dbd1aae6e2a47af68e987dbfcc91c564d17c532e892938983eac8f891dec81b9 Reported operators
In recent campaigns, vjw0rm and STRRAT also leveraged task creation and adding entries to the registry.
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.