Self-Propagating Malware Spreading Via WhatsApp, Targets Brazilian Users
ID: e04f3dbe-c67b-59b5-ba56-b08e284be588
STIX ID: report--e04f3dbe-c67b-59b5-ba56-b08e284be588
Feed Name: TrendAI Security Blog
TrendAI™ Research describes the Water Saci campaign (malware family SORVEPOTEL), an active Brazil-focused malware campaign that spreads via WhatsApp and email ZIP attachments, uses LNK/PowerShell/.NET multi-stage loaders and shellcode injection to deploy banking-focused info-stealers and a WhatsApp hijack module that automates propagation and uses advanced overlay phishing to harvest credentials; the report includes technical analysis, IoCs, affected sectors, and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
