Skip to content

Vjw0rm

Vjw0rm is a commodity JavaScript remote access trojan (RAT) first seen around 2016 and originally associated with an author known as "v-j." It uses Windows Script Host components including WScript.Shell, ActiveXObject, and MSScriptControl for execution and dynamic scripting.

Profile source: Mallory opens in a new tab

Vjw0rm

Family profile

Vjw0rm is a commodity JavaScript remote access trojan (RAT) first seen around 2016 and originally associated with an author known as "v-j." It uses Windows Script Host components including WScript.Shell, ActiveXObject, and MSScriptControl for execution and dynamic scripting. Documented capabilities include command execution, file operations, registry operations, environment reconnaissance, WMI-based security product enumeration, and self-propagation to USB or network locations. Reporting cited in the content also notes that malware used in TA2541 campaigns, including vjw0rm, supports information gathering and remote control of infected machines.

The malware has been observed in phishing-driven intrusion chains associated with TA2541, a financially motivated cybercriminal actor active since at least 2017. TA2541 has targeted aviation, aerospace, transportation, manufacturing, and defense organizations, typically using aviation-, transportation-, and travel-themed lures delivered via high-volume email campaigns. In these campaigns, vjw0rm has been delivered through chains involving obfuscated VBS files, PowerShell, cloud-hosted payloads, and persistence via scheduled tasks and Windows Registry Run keys. Proofpoint specifically observed recent vjw0rm campaigns leveraging task creation and registry persistence.

A separate 2026 campaign described in the content used a WinRAR self-extracting archive disguised as a software keygen to deploy Vjw0rm through a four-layer dropper chain. The outer archive silently executed a decoy KeyGen.exe and a nested Patch.exe SFX archive. Patch.exe dropped setup.exe, a compiled AutoHotkey orchestrator, along with approximately 200 legitimate Windows troubleshooting pack files used as camouflage. The orchestrator staged payloads under C:\ProgramData\Adobe\AIR\Logs\gp\PerfLogs\Google\start\ and C:\Users\Public\Settings\A\News\, then launched win.ps1, Script.js, Patch.js, and a renamed WindowsUpdater.js in parallel. win.ps1 and Script.js both retrieved content from hxxps://upaste[.]me/r/8dc960578b490d703, which functioned as a dead-drop resolver. Script.js established persistence by copying itself to %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\Script.js, while Patch.js created scheduled tasks and used Unicode fullwidth character obfuscation. The final RAT core was embedded locally as PCWDiagnostic.xml (SHA256 33629caa9918c81a5e1ce58c1682e7465ac6f4bccd8d9c13d429249920c6d557), renamed to WindowsUpdater.js, and executed as Vjw0rm. Additional artifacts from this campaign include outer SFX SHA256 64a92d23f6efcc17cdd3016a52e0503a13350f037785220a08b74b46333a3eee, nested Patch.exe SHA256 4a341185e5e0983feca8a39b65b92a6d69b72d2093aa1a1b134b39d63a1c9a96, setup.exe SHA256 0419d91f867968fce085b3a1bbe3c3dc96e1b83e8e8c27d4a5d4e64be1389dcc, and GUID 34892937-8948-47dc-9c73-e8f5c918f49a in Patch.js. Turkish-language artifacts in the SFX comment suggested a likely Turkish-speaking commodity cybercrime operator.

The content also notes that Vjw0rm has appeared in broader commodity malware delivery ecosystems beyond TA2541, including campaigns documented by Proofpoint and Positive Technologies and activity associated with the RevengeHotels/TA558 cluster, where it was one of several RATs delivered in campaigns targeting hospitality and travel-related victims.

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 23, 2026
Last activity
Jul 28, 2026
Feed role
C2
Host form
3 IP / 31 hostnames

Leading locations

  • US24
  • DE3
  • IE3
  • RU2
  • SE1

Leading providers

  • Amazon.com, Inc.10
  • Amazon.com, Inc.10
  • IONOS SE3
  • Akamai Connected Cloud2
  • Google LLC2
  • Smart Technology LLC2

Infrastructure traits

  • Hosting 33
  • Vpn 5

Samples

Recent associated samples

Reported operators

Threat actors

1 named in public reporting
TA2541

In recent campaigns, vjw0rm and STRRAT also leveraged task creation and adding entries to the registry.

MITRE ATT&CK

Vjw0rm in ATT&CK

17 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.