Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

New WhatsApp Worm Attacks Users with Banking Malware to Users Login Credentials

Security researchers have discovered a malware campaign exploiting WhatsApp's messaging platform to deploy banking trojans targeting Brazilian financial institutions and cryptocurrency exchanges.

Security researchers have discovered a malware campaign exploiting WhatsApp's messaging platform to deploy banking trojans targeting Brazilian financial institutions and cryptocurrency exchanges.

The self-propagating worm, which emerged on Fri, Sep 29, 2025, demonstrates advanced evasion techniques and multi-stage infection chains designed to circumvent modern security defenses.

The threat has affected over 400 customer environments across more than 1,000 endpoints, highlighting the campaign's widespread reach and effectiveness.

The attack initiates when victims receive a malicious ZIP archive through WhatsApp Web from a previously infected contact.

The social engineering aspect is particularly effective, as the message claims the attached content can only be viewed on a computer, prompting recipients to download and execute the malware on desktop systems rather than mobile devices.

This strategic approach ensures the malware operates in an environment where it can establish persistence and deploy its full payload capabilities.

Sophos analysts identified the malware's sophisticated infection mechanism during their investigation of multiple incidents across Brazil.

The threat has affected over 400 customer environments across more than 1,000 endpoints, highlighting the campaign's widespread reach and effectiveness.
Amanda Parks · Thehackingpost

The threat actors demonstrate a deep understanding of Windows security architecture and PowerShell capabilities, implementing obfuscation techniques that allow the malware to operate undetected for extended periods.

The campaign's technical sophistication suggests the involvement of experienced cybercriminals with substantial resources and knowledge of Brazilian banking systems.

Multi-Stage PowerShell Infection Chain

The malware's execution begins with a malicious Windows LNK file hidden within the ZIP archive. When executed, the LNK file contains an obfuscated Windows command that constructs and runs a Base64-encoded PowerShell command.

This first-stage PowerShell script covertly launches an Explorer process that downloads the next-stage payload from command and control servers, including hxxps[:]//www.zapgrande[.]com, expansiveuser[.]com, and sorvetenopote[.]com.

The second-stage PowerShell command demonstrates the malware's defensive evasion capabilities through explicit security control modifications.

Advertisement

Portuguese-language comments embedded within the PowerShell code reveal the author's intentions to "add an exclusion in Microsoft Defender" and "disable UAC" (User Account Control).

These modifications create a permissive environment where the malware can operate without triggering security alerts or requiring user interaction for privileged operations.

The campaign delivers two distinct payloads depending on the infected system's characteristics: a legitimate Selenium browser automation tool with matching ChromeDriver, and a banking trojan named Maverick.

The Selenium payload enables attackers to control active browser sessions, facilitating WhatsApp web session hijacking and enabling the worm's self-propagation mechanism.

Meanwhile, the Maverick banking trojan monitors browser traffic for connections to Brazilian banks and cryptocurrency exchanges, deploying additional .NET-based banking malware when financial targets are accessed.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories