Mohammedia – A new malware campaign is moving quickly across Brazil, using WhatsApp messages to infect users and reach their friends, families, and colleagues. Security researchers say the scheme combines social engineering, automated spreading, and a powerful banking-and-crypto trojan.
The attack is hitting everyday users, and its success relies on a simple pattern — a trusted message, a single click, and a session that instantly falls into the hands of attackers.
The infection usually begins with a WhatsApp message containing a ZIP file or a .lnk shortcut. The file is presented as something normal and familiar, such as a receipt, a medical note, or an administrative document.
Once opened, a hidden script runs in the background and takes control of the victim’s WhatsApp Web session. Within seconds, the same malicious file is forwarded to the victim’s entire contact list.
This method turns each new victim into another sender, creating a worm-like chain reaction that spreads quickly across personal and professional circles.
Researchers describe the attack as a two-part system. A Python component manages the propagation through WhatsApp Web, while an MSI installer delivers a second payload called the “Eternidade Stealer.”
This module silently collects personal data and enables the attackers to control key parts of the device. The operators behind the scam continuously update their messages, adjust commands, and pull address books through a remote command-and-control server.
The campaign also fits into a wider pattern seen in Brazil over recent months, with similar families like Maverick, Coyote, and SORVEPOTEL exploiting WhatsApp Web and browser manipulation techniques to target local users.
A Trojan built for banking and crypto theft
Once installed, the banking and crypto-stealing component activates. It collects passwords, cookies, one-time codes, and other sensitive information.
It can push web injections to interfere with online banking, and it looks for recovery phrases and seed keys linked to cryptocurrency wallets or extensions.
The goal is to drain bank accounts when victims reconnect and seize crypto wallets whenever a signing request appears on-screen.
Because the attackers control the active session and use trusted contacts to spread messages, many victims do not suspect a problem until money is already missing.
The attackers’ strategy takes advantage of everyday digital habits. Many people switch between desktop apps, browser extensions, and mobile phones without realizing that this mix increases their attack surface.
The malware also utilizes convincing social-engineering templates — ranging from delivery notices to government messages — to persuade victims into opening files they believe come from someone they trust.
There are several early warning signs. WhatsApp may send files without user action; the browser may slow down or display unusual pop-ups; and antivirus tools may flag unexpected PowerShell or VBS scripts. Unknown extensions may suddenly appear in the browser.
Experts recommend disconnecting WhatsApp Web on all devices as soon as any suspicious behavior appears.
Users should then change their banking and crypto passwords from a clean machine, revoke active sessions on wallets, and restore systems from a safe backup if needed.
Avoiding WhatsApp ZIP attachments, enabling two-step verification, and separating trading devices from everyday use can significantly reduce the risk.
Researchers say the campaign moves fast. For many users, quick reactions will be the difference between a minor scare and a chain of costly compromises.
Read Also: ICIJ Exposes How Top Crypto Exchanges Enabled $9.3 Billion Scam Epidemic








