Vjw0rm is a commodity Windows remote access trojan implemented in JavaScript and executed through Windows Script Host. Active since at least the mid-2010s, it has been widely used in cybercrime campaigns and is commonly associated with phishing-driven malware delivery. The malware has appeared in operations attributed to actors such as TA558 and TA2541, including campaigns targeting hospitality, travel, aviation, aerospace, transportation, manufacturing, and defense organizations, with notable activity against Portuguese- and Spanish-speaking victims in Latin America as well as broader global targeting.
Vjw0rm is typically delivered through phishing lures, malicious archives, script-based loaders, and multi-stage chains involving VBScript, PowerShell, AutoHotkey, or containerized attachments. Observed campaigns have used reservation, invoice, travel, and judicial-notification themes, as well as cracked-software and keygen lures. It has also been staged through paste and text-sharing services and delivered by loader chains that abuse legitimate utilities, nested self-extracting archives, and script obfuscation.
Functionally, Vjw0rm provides remote control over infected Windows systems. Documented capabilities include command execution, file operations, registry manipulation, environment reconnaissance, WMI-based enumeration of security products, and self-propagation to removable or network-accessible locations. Campaigns delivering Vjw0rm have also used persistence mechanisms such as Startup-folder scripts, scheduled tasks, and Registry Run entries. Its role in intrusion chains is consistent with post-compromise remote administration, information gathering, follow-on payload delivery, and broader criminal monetization.
Vjw0rm is frequently discussed alongside Houdini, and the names are sometimes used together in reporting on shared delivery chains. It is also distinct from njRAT despite historical naming overlap in some ecosystems involving similar “-w0rm” nomenclature. Overall, Vjw0rm remains a long-lived, adaptable commodity RAT that continues to circulate in phishing and loader-based campaigns because of its low barrier to use, flexible scripting-based implementation, and compatibility with common Windows tradecraft.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Since 2018, this group has used consistent tactics, techniques, and procedures to attempt to install a variety of malware including Loda RAT, Vjw0rm, and Revenge RAT.
In recent campaigns, vjw0rm and STRRAT also leveraged task creation and adding entries to the registry.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
The actor sends malicious emails written in Portuguese, Spanish, and sometimes English. The emails use reservation-themed lures with business-relevant themes such as hotel room bookings.
TA2541 has also established persistence by creating scheduled tasks... In recent campaigns, vjw0rm and STRRAT also leveraged task creation... Scheduled Task: schtasks.exe /Create /TN "Updates\BQVIiVtepLtz" /XML C:\Users\[User]\AppData\Local\Temp\tmp7CF8.tmp
The functionalities of the implemented commands include: ... execute commands using cmd and powershell ... Depending on the downloaded file’s extension, it can be executed using wscript.exe, java.exe, and cmd.exe ... The RAT executes a command transmitted by the C2 server using cmd.exe ... the sent command is run via powershell.exe.
If executed, PowerShell pulls an executable from a text file hosted on various platforms such as Pastetext, Sharetext, and GitHub. The threat actor executes PowerShell into various Windows processes and queries Windows Management Instrumentation (WMI) for security products such as antivirus and firewall software, and attempts to disable built-in security protections.
They also added the ability to disable Microsoft Defender by dropping a Batch script and an LNK file pointing to that script.
The attacker uses VBsEdit to convert the VjW0rm and Houdini VBScript into an executable.
Execution Command and Scripting Interpreter: JavaScript T1059.007 Script.js, Patch.js, WindowsUpdater.js (Vjw0rm)
The RAT delivery campaign starts from an AutoHotKey compiled script... all of which start with an AHK executable that leads to the different VBScripts that eventually load the RAT.
TA2541 has also established persistence by creating scheduled tasks... In recent campaigns, vjw0rm and STRRAT also leveraged task creation... Scheduled Task: schtasks.exe /Create /TN "Updates\BQVIiVtepLtz" /XML C:\Users\[User]\AppData\Local\Temp\tmp7CF8.tmp
TA2541 has also established persistence by creating scheduled tasks... In recent campaigns, vjw0rm and STRRAT also leveraged task creation... Scheduled Task: schtasks.exe /Create /TN "Updates\BQVIiVtepLtz" /XML C:\Users\[User]\AppData\Local\Temp\tmp7CF8.tmp
TA2541 has also established persistence by creating scheduled tasks and adding entries in the registry... Registry: Key: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\svchost Data: C:\Users[User]\AppData\Roaming\server\server.exe
The RAT is delivered by an obfuscated VBScript... This script deobfuscates a PowerShell command... In this version, the attacker added a hexadecimal obfuscation layer to the VBScript
In this campaign, the attackers incorporate malicious scripts/executables alongside a legitimate application to disguise their intentions.
Defense Evasion Masquerading: Rename System Utilities T1036.003 Legitimate directory names (Adobe, PerfLogs, Google)
Defense Evasion Masquerading: Match Legitimate Name T1036.005 PCWDiagnostic.xml, WindowsUpdater directory, Adobe/Google paths
The second drops and executes a VBScript that terminates wscript.exe processes to clean traces of a failed attempt to perform the previous VBScript.
Defense Evasion Indicator Removal: File Deletion T1070.004 Potential cleanup after execution
Command and Control Application Layer Protocol: Web Protocols T1071.001 HTTPS download from upaste[.]me
73 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
VJW0rm is the malware being distributed via a phishing campaign themed as a judicial notification.
Commodity JavaScript remote access trojan/worm that runs via Windows Script Host. In this campaign it is deployed through a multi-layer dropper chain and provides command execution, COM automation, dynamic scripting via MSScriptControl, persistence, file and registry operations, WMI-based security product enumeration, environment reconnaissance, and self-propagation via USB/network spread.
Vjw0rm is a remote access trojan used for remote control and data theft, deployed in phishing campaigns against the hospitality sector.
A remote access trojan delivered via AutoHotKey and VBScript launcher chains, using manifest hijacking and other evasion techniques.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.