Microsoft Set to Retire Grunge-Era VBScript, to Cybercrimes Chagrin - Dark Reading

2023-10-12 16:11 (EST) - Managing Editor

Microsoft announced this week that its deprecating the timeworn VBScript — bad news for cybercriminals, for whom its a favorite tool.

In future releases of Windows, VBScript will be available only as a feature on demand; and eventually, it will be removed from the operating system altogether.

The VBScript programming language, short for Visual Basic Script, is nearly 30 years old, having been introduced in the mid-90s as a lightweight way to natively generate programming scripts. But like grunge fashion and Neve Campbell movies, its pre-Y2K moment in the sun is long past.

Yet cybercriminals continue to use it as an avenue for initial access to targets, especially since Microsoft started blocking macros by default. Threat actors quickly discovered after its release that they could create malicious VBScripts that would run natively and unquestioned on Windows machines, which could help them smuggle in any number of remote access Trojans, downloaders, and more.

An early example of this was the "ILoveYou" worm from 2000, but more recent malware "gettin VBS-y wit it" (to malaprop another mid-90s sensation) include Emotet, QakBot, and Dark Gate.

That class of malwares days now appear to be numbered.

"Initially, the VBScript feature on demand will be preinstalled to allow for uninterrupted use while you prepare for the retirement of VBScript," according to the official announcement from Redmond. In other words, for the interim period before full discontinuation, it will be disabled by default, but users can choose to turn it on if they wish.

Microsoft didnt provide a timeline for when it plans full removal of the tool.

Source

Previous
Previous

CISA ‘working in partnership’ with Israeli cyber counterparts after Hamas attack, executive director says - Fedscoop

Next
Next

Brands Beware: Xs New Badge System Is a Ripe Cyber-Target - Dark Reading