logo

Stealer in the status bar.

ID: 40be9edd-15ed-5c08-8368-6b7d0ea49a74

STIX ID: report--40be9edd-15ed-5c08-8368-6b7d0ea49a74

Feed Name: The CyberWire

Threat Score
75/100

Date Published: 2026-02-14

Date Updated: 2026-04-23

...
...

LevelBlue SpiderLabs identified a new Brazilian banking trojan called "Eternidade Stealer" that is propagated through WhatsApp hijacking and social engineering using a Python-based worm to harvest contacts and spread malicious MSI installers. The Delphi-compiled malware targets Brazilian users, retrieves its command-and-control via IMAP, uses encrypted C2 and process injection for stealth and persistence, and deploys banking overlays to harvest credentials from financial institutions and cryptocurrency platforms.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.