logo

Maverick Fileless Trojan Turns Infected Phones into WhatsApp Worms to Steal Banking and UPI Credentials

ID: e5bc7fd7-8c36-53c0-8285-cbe0c3f9ce74

STIX ID: report--e5bc7fd7-8c36-53c0-8285-cbe0c3f9ce74

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2025-10-17

Date Updated: 2026-04-22

Author: Ddos

...
...

Kaspersky GReAT uncovered a large fileless banking Trojan campaign in Brazil distributing a new threat called 'Maverick' via WhatsApp ZIP attachments containing malicious LNK shortcuts that launch PowerShell to load all stages in memory. Maverick performs geochecks to limit infections to Brazilian systems, uses WPPConnect to self-propagate through hijacked WhatsApp Web sessions, targets dozens of Brazilian banks and crypto platforms with capabilities such as screenshots, keylogging, input control and phishing overlays, communicates with C2 over SSL with custom certificates and authentication, stores only a small bootstrap in Startup for persistence, and Kaspersky telemetry reported ~62,000 blocked infection attempts in the first ten days of October 2025.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.