Threat Actors Exploit WhatsApp Messages to Target Windows Systems with SORVEPOTEL Malware
ID: 0df3e2c1-5aff-58fa-a3cb-62816e253e17
STIX ID: report--0df3e2c1-5aff-58fa-a3cb-62816e253e17
Feed Name: Cyber Press
Threat Score
**Executive Summary:** SORVEPOTEL is an active Windows-targeting malware campaign concentrated in Brazil that spreads via compromised WhatsApp accounts by sending ZIP attachments with malicious .LNK shortcuts which run obfuscated PowerShell to fetch additional modules, maintain persistence, and automatically resend the malicious archive to contacts and groups; the report includes IoCs, targeted sectors, and mitigation advice.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
