Skip to content

Vjw0rm

Vjw0rm is a commodity Windows remote access trojan implemented in JavaScript and executed through Windows Script Host.

Profile source: Mallory opens in a new tab

Vjw0rm

Family profile

Vjw0rm is a commodity Windows remote access trojan implemented in JavaScript and executed through Windows Script Host. Active since at least the mid-2010s, it has been widely used in cybercrime campaigns and is commonly associated with phishing-driven malware delivery. The malware has appeared in operations attributed to actors such as TA558 and TA2541, including campaigns targeting hospitality, travel, aviation, aerospace, transportation, manufacturing, and defense organizations, with notable activity against Portuguese- and Spanish-speaking victims in Latin America as well as broader global targeting.

Vjw0rm is typically delivered through phishing lures, malicious archives, script-based loaders, and multi-stage chains involving VBScript, PowerShell, AutoHotkey, or containerized attachments. Observed campaigns have used reservation, invoice, travel, and judicial-notification themes, as well as cracked-software and keygen lures. It has also been staged through paste and text-sharing services and delivered by loader chains that abuse legitimate utilities, nested self-extracting archives, and script obfuscation.

Functionally, Vjw0rm provides remote control over infected Windows systems. Documented capabilities include command execution, file operations, registry manipulation, environment reconnaissance, WMI-based enumeration of security products, and self-propagation to removable or network-accessible locations. Campaigns delivering Vjw0rm have also used persistence mechanisms such as Startup-folder scripts, scheduled tasks, and Registry Run entries. Its role in intrusion chains is consistent with post-compromise remote administration, information gathering, follow-on payload delivery, and broader criminal monetization.

Vjw0rm is frequently discussed alongside Houdini, and the names are sometimes used together in reporting on shared delivery chains. It is also distinct from njRAT despite historical naming overlap in some ecosystems involving similar “-w0rm” nomenclature. Overall, Vjw0rm remains a long-lived, adaptable commodity RAT that continues to circulate in phishing and loader-based campaigns because of its low barrier to use, flexible scripting-based implementation, and compatibility with common Windows tradecraft.

Capabilities

  • Defense Evasion
  • Lateral Movement
  • Persistence
  • Post Exploitation
  • Reconnaissance
  • Spoofing

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 10, 2026
Last activity
Sep 14, 2026
Feed role
C2
Host form
1 IP / 29 hostnames

Leading locations

  • US24
  • IE3
  • RU2
  • SE1

Leading providers

  • Amazon.com, Inc.10
  • Amazon.com, Inc.10
  • Akamai Connected Cloud2
  • Google LLC2
  • Smart Technology LLC2
  • 1337 Services GmbH1

Infrastructure traits

  • Hosting 27
  • Vpn 1

Samples

Recent associated samples

Reported operators

Threat actors

2 named in public reporting
TA558

Since 2018, this group has used consistent tactics, techniques, and procedures to attempt to install a variety of malware including Loda RAT, Vjw0rm, and Revenge RAT.

TA2541

In recent campaigns, vjw0rm and STRRAT also leveraged task creation and adding entries to the registry.

MITRE ATT&CK

Vjw0rm in ATT&CK

28 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.