logo

Threat Actors Exploit WhatsApp Messages to Target Windows Systems with SORVEPOTEL Malware

ID: 0df3e2c1-5aff-58fa-a3cb-62816e253e17

STIX ID: report--0df3e2c1-5aff-58fa-a3cb-62816e253e17

Feed Name: Cyber Press

Threat Score
70/100

Date Published: 2025-10-03

Date Updated: 2026-04-19

Author: Priya

...
...

**Executive Summary:** SORVEPOTEL is an active Windows-targeting malware campaign concentrated in Brazil that spreads via compromised WhatsApp accounts by sending ZIP attachments with malicious .LNK shortcuts which run obfuscated PowerShell to fetch additional modules, maintain persistence, and automatically resend the malicious archive to contacts and groups; the report includes IoCs, targeted sectors, and mitigation advice.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.