logo

New Malware Via WhatsApp Exfiltrate Contacts to Attack Server and Deploys Malware

ID: 9dab1eb0-812d-599d-8570-14c83df0f3c1

STIX ID: report--9dab1eb0-812d-599d-8570-14c83df0f3c1

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2025-11-20

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Trustwave SpiderLabs identified 'Eternidade Stealer', a sophisticated Delphi banking trojan distributed via obfuscated VBScript and WhatsApp hijacking that installs a Python-based WhatsApp worm and an MSI payload. The malware harvests WhatsApp contacts (filtering for personal contacts), exfiltrates them to C2, uses IMAP-based email retrieval for dynamic C2 updates, performs system reconnaissance, enforces a Brazilian Portuguese locale check, and deploys banking overlay screens to steal credentials from 40+ Brazilian financial services and exchanges—creating a high-risk targeted campaign with potential wider global activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.