Unraveling Water Saci's New Multi-Format, AI-Enhanced Attacks Propagated via WhatsApp
ID: 6d93bc66-008d-54f0-a656-c9ed83594142
STIX ID: report--6d93bc66-008d-54f0-a656-c9ed83594142
Feed Name: TrendAI Security Blog
This report analyzes the Water Saci campaign that leverages WhatsApp social engineering to deliver multi-format payloads (HTA, ZIP, PDF) which install an MSI-based AutoIt loader that decrypts and injects a banking trojan targeting Brazilian banks and cryptocurrency platforms; the campaign includes robust persistence, anti-sandbox checks, IMAP-based C2 retrieval, extensive backdoor commands, and automation for mass propagation via a Python WhatsApp automation script (converted from PowerShell).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
