New Banking Malware Exploits WhatsApp to Hijack Your Computer Remotely
## Cybersecurity: Malware Campaign Targeting Brazilian Users
Cybersecurity: Malware Campaign Targeting Brazilian Users
Cybersecurity researchers have identified an advanced malware campaign targeting Brazilian users via WhatsApp, deploying a new banking Trojan known as "Maverick."
The campaign blocked over 62,000 infection attempts in Brazil during the first ten days of October, highlighting its extensive scale and potential impact.
The attack initiates when victims receive a malicious ZIP file through WhatsApp messages, containing an LNK file disguised as a legitimate bank document. These files use Portuguese-language filenames to appear credible.
Victims are often instructed to view the file on a computer and bypass security warnings by selecting "keep file."
Maverick's self-propagating mechanism is particularly dangerous. Once installed, it uses WPPConnect, an open-source WhatsApp automation tool, to hijack victims' accounts and automatically send the malicious files to their contacts via WhatsApp Web.
This worm-like behavior facilitates rapid spread across the platform, turning each infected user into a distributor of the malware.
The infection process is sophisticated, operating mainly in memory to leave minimal traces on disk. The initial LNK file executes a series of PowerShell scripts that download encrypted payloads from command-and-control servers.
The malware uses multiple verification layers, including User-Agent validation, to ensure downloads originate only from the malware itself, complicating efforts for security researchers to obtain samples.
The attack initiates when victims receive a malicious ZIP file through WhatsApp messages, containing an LNK file disguised as a legitimate bank document.
The operation employs modular components loaded through PowerShell, .NET assemblies, and Donut-encrypted shellcode, culminating in the deployment of the Maverick banking Trojan.
The malware targets Brazilian users by verifying the victim's time zone, language settings, regional configuration, and date format before proceeding with installation.
Researchers have found evidence that artificial intelligence was utilized in Maverick's development, particularly in certificate decryption routines and general code structure.
To communicate with its API, Maverick sends the API key in the “X-Request-Headers” field of the HTTP request header.
Once active, Maverick monitors victims' browsers for access to 26 Brazilian banking websites, six cryptocurrency exchanges, and one payment platform. It supports major browsers, including Chrome, Firefox, Microsoft Edge , Brave, and Internet Explorer.
The malware's capabilities include capturing screenshots, logging keystrokes, controlling the mouse, monitoring browsing activity, terminating processes, and displaying overlay phishing pages when accessing banking websites. These features allow attackers to capture banking credentials and execute unauthorized transactions while maintaining remote control over infected computers.
Significant code overlaps were identified between Maverick and another Brazilian banking Trojan called Coyote, documented in early 2024. Both threats share similar encryption mechanisms using AES-256 and employ comparable communication protocols. However, Maverick's architectural differences suggest it represents either a complete refactoring of Coyote or a new threat developed using shared code libraries.
This development represents a concerning evolution in malware, where threat actors use AI tools to create more sophisticated threats.
Users should remain vigilant regarding unsolicited files received through WhatsApp, even from known contacts whose accounts may be compromised.
Organizations should implement email and messaging security solutions capable of detecting malicious LNK files, maintain updated antivirus software, and educate users about the risks of downloading and executing files from messaging platforms.
Brazilian banking customers should exercise caution and verify any suspicious banking-related messages through official channels before taking action.
Based on reporting by GBHackers.
