logo

Self-Propagating Malware Spreading Via WhatsApp, Targets Brazilian Users

ID: e04f3dbe-c67b-59b5-ba56-b08e284be588

STIX ID: report--e04f3dbe-c67b-59b5-ba56-b08e284be588

Feed Name: TrendAI Security Blog

Threat Score
78/100

Date Published: 2026-01-01

Date Updated: 2026-08-06

...
...

TrendAI™ Research describes the Water Saci campaign (malware family SORVEPOTEL), an active Brazil-focused malware campaign that spreads via WhatsApp and email ZIP attachments, uses LNK/PowerShell/.NET multi-stage loaders and shellcode injection to deploy banking-focused info-stealers and a WhatsApp hijack module that automates propagation and uses advanced overlay phishing to harvest credentials; the report includes technical analysis, IoCs, affected sectors, and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.