logo

Self-Propagating Malware Hits WhatsApp Users in Brazil

ID: 673e68ab-992e-5453-8657-640bd5f48ce3

STIX ID: report--673e68ab-992e-5453-8657-640bd5f48ce3

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2025-10-06

Date Updated: 2026-05-08

Author: Elizabeth Montalbano, Contributing Writer

...
...

Trend Micro researchers describe the Water Saci campaign, an active, self‑propagating infection primarily in Brazil that delivers the Sorvepotel infostealer via malicious ZIP attachments spread through compromised WhatsApp desktop sessions. The attack uses .LNK shortcuts to run PowerShell that downloads shellcode and injects into powershell_ise.exe, monitors browser URLs for targeted Brazilian banking and cryptocurrency sites to steal credentials, and automatically distributes the same ZIP to all contacts and groups on infected WhatsApp Web sessions; recommended mitigations include disabling WhatsApp auto‑downloads, restricting personal messaging apps on corporate devices, enforcing application whitelisting or containerization for BYOD, and user awareness training.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.