Last seven days
- First activity
- Sep 10, 2026
- Last activity
- Sep 14, 2026
- Feed role
- C2
- Host form
- 1 IP / 29 hostnames
Vjw0rm is a commodity Windows remote access trojan implemented in JavaScript and executed through Windows Script Host.
Profile source: Mallory opens in a new tabVjw0rm
Vjw0rm is a commodity Windows remote access trojan implemented in JavaScript and executed through Windows Script Host. Active since at least the mid-2010s, it has been widely used in cybercrime campaigns and is commonly associated with phishing-driven malware delivery. The malware has appeared in operations attributed to actors such as TA558 and TA2541, including campaigns targeting hospitality, travel, aviation, aerospace, transportation, manufacturing, and defense organizations, with notable activity against Portuguese- and Spanish-speaking victims in Latin America as well as broader global targeting.
Vjw0rm is typically delivered through phishing lures, malicious archives, script-based loaders, and multi-stage chains involving VBScript, PowerShell, AutoHotkey, or containerized attachments. Observed campaigns have used reservation, invoice, travel, and judicial-notification themes, as well as cracked-software and keygen lures. It has also been staged through paste and text-sharing services and delivered by loader chains that abuse legitimate utilities, nested self-extracting archives, and script obfuscation.
Functionally, Vjw0rm provides remote control over infected Windows systems. Documented capabilities include command execution, file operations, registry manipulation, environment reconnaissance, WMI-based enumeration of security products, and self-propagation to removable or network-accessible locations. Campaigns delivering Vjw0rm have also used persistence mechanisms such as Startup-folder scripts, scheduled tasks, and Registry Run entries. Its role in intrusion chains is consistent with post-compromise remote administration, information gathering, follow-on payload delivery, and broader criminal monetization.
Vjw0rm is frequently discussed alongside Houdini, and the names are sometimes used together in reporting on shared delivery chains. It is also distinct from njRAT despite historical naming overlap in some ecosystems involving similar “-w0rm” nomenclature. Overall, Vjw0rm remains a long-lived, adaptable commodity RAT that continues to circulate in phishing and loader-based campaigns because of its low barrier to use, flexible scripting-based implementation, and compatibility with common Windows tradecraft.
C2 tracking
Derp observations, rolling seven-day window
Samples
08f2c963906b126c0a10b47aa28eccebf8e209f3885c54489f771e948dc89b1a 142f914955c7bee7fdd0520d6b6310aba3c986643fa4f1b8b6db6d79354492b3 3d35e3de4f61106fc2dda44ff477e1e6ff8409c62dc1573fedd6f459f1da46b6 4afd77e8fe74003eb2e36537e637ef06fdf21ab5e64a4a76a034ba34354e8894 8f367923fa8f8ccfe69cb683a8723380722b20f704f5d2b0cc7fdaf4400e614c a4256c0e812f6d3039989c03186930dffc3c76650f06022db6b88d94a05fb39b a8cb210eb033b328e9e282fe531122fbebe3b0fdcddd7f52805875ab6befa07d ad01f2854ce7575b04b6d0dac52ead0c5c11d0a5862b678dc58cd6ef813eccca b379b4d4540dac461f02bed89d37579359176a58fa0a5da9c1b266bf31b2e8ba cf3736b520a7906911993f72f5306a565807fd4be89c8f90a7dbf41aa6cf2d02 Reported operators
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.