logo

SpiderLabs IDs New Banking Trojan Distributed Through WhatsApp

ID: 5b935a74-dec7-5d7d-aa35-0ebf2f4ed1cb

STIX ID: report--5b935a74-dec7-5d7d-aa35-0ebf2f4ed1cb

Feed Name: LevelBlue SpiderLabs Blog

Threat Score
75/100

Date Published: 2025-11-19

Date Updated: 2026-04-28

Author: Nathaniel Morales, John Basmayor, and Nikita Kazymirskyi

...
...

SpiderLabs researchers identified and dissected the Eternidade Stealer campaign targeting Brazilian users: a WhatsApp-propagating Python worm delivers a malicious MSI that installs Delphi-based malware which harvests credentials, monitors for banking/wallet apps, deploys overlays, and retrieves dynamic C2s via IMAP; the report includes technical analysis, attacker TTPs, infrastructure findings, and multiple IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.