Skip to content

Vjw0rm

Vjw0rm is a commodity Windows remote access trojan implemented in JavaScript and commonly executed through Windows Script Host.

Profile source: Mallory opens in a new tab

Vjw0rm

Family profile

Vjw0rm is a commodity Windows remote access trojan implemented in JavaScript and commonly executed through Windows Script Host. Active since at least 2016, it is associated with broad cybercriminal distribution rather than a single exclusive operator. The malware provides remote control and information-gathering capabilities on infected systems, including command execution, file and registry operations, environment reconnaissance, and security-product enumeration via WMI. Reported variants and campaigns have also supported self-propagation to USB and network locations.

Vjw0rm has been delivered through multiple social-engineering and malware-staging chains. Documented delivery methods include phishing campaigns, including judicial-notification lures and broader travel-, aviation-, and transportation-themed email operations, as well as cracked-software or keygen lures packaged in multi-stage archive-based droppers. In observed Windows infections, Vjw0rm has been launched through layered script execution involving PowerShell, JScript/VBScript hybrids, AutoHotkey-based orchestration, and dead-drop style retrieval from paste services.

Persistence mechanisms observed in Vjw0rm-related campaigns include startup-folder script placement, scheduled tasks, and Windows registry Run-key style persistence. The malware has been linked to campaigns attributed to TA2541, a financially motivated cybercriminal actor known for targeting aviation, aerospace, transportation, manufacturing, and defense organizations with commodity RATs. Vjw0rm has also appeared in broader commodity malware ecosystems used against other sectors through phishing and lure-based delivery. Its continued use reflects the durability of script-based RATs that combine low development cost, flexible staging chains, and effective post-compromise remote administration on Windows hosts.

Capabilities

  • Defense Evasion
  • Persistence
  • Post Exploitation
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 3, 2026
Last activity
Aug 6, 2026
Feed role
C2
Host form
0 IP / 30 hostnames

Leading locations

  • US25
  • IE3
  • RU2

Leading providers

  • Amazon.com, Inc.10
  • Amazon.com, Inc.10
  • 1337 Services GmbH2
  • Akamai Connected Cloud2
  • Google LLC2
  • Smart Technology LLC2

Infrastructure traits

  • Hosting 30
  • Vpn 4

Samples

Recent associated samples

Reported operators

Threat actors

1 named in public reporting
TA2541

In recent campaigns, vjw0rm and STRRAT also leveraged task creation and adding entries to the registry.

MITRE ATT&CK

Vjw0rm in ATT&CK

17 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.