Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

WhatsApp Exploited to Spread SORVEPOTEL Malware on Windows Systems

An ongoing malware campaign identified as SORVEPOTEL is targeting Windows systems through WhatsApp messages, primarily affecting users in Brazil. This malware is designed to spread rapidly rather than steal data or demand ransomware payments, leveraging…

An ongoing malware campaign identified as SORVEPOTEL is targeting Windows systems through WhatsApp messages, primarily affecting users in Brazil. This malware is designed to spread rapidly rather than steal data or demand ransomware payments, leveraging social engineering and automation techniques.

According to Trend Research telemetry, the majority of the 477 identified infections are located in Brazil, impacting government, public service, manufacturing, technology, education, and construction sectors. The infection process begins when a user receives a phishing message on WhatsApp from a compromised contact. These messages, written in Portuguese, often include a ZIP archive that appears to be a legitimate document.

In addition to WhatsApp, email has been identified as an alternative vector, with phishing emails distributing similarly named ZIP attachments. Inside these ZIP files is a Windows shortcut (.LNK) file that, when opened, executes a PowerShell or command-line script. This script downloads the primary malware payload from attacker-controlled domains, which are disguised using typo-squatted URLs.

The downloaded payload is typically a batch (.BAT) script that ensures persistence by copying itself into the Windows Startup folder. This script then executes an obfuscated PowerShell command, utilizing Base64 encoding. The script communicates with command-and-control (C&C) servers to download and execute additional in-memory payloads, minimizing forensic traces.

An ongoing malware campaign identified as SORVEPOTEL is targeting Windows systems through WhatsApp messages, primarily affecting users in Brazil.
William Hayes · Thehackingpost

Despite its sophisticated delivery mechanisms, current campaign activities show no evidence of data exfiltration or file encryption. The focus remains on self-propagation.

SORVEPOTEL detects active WhatsApp Web sessions and automatically forwards the malicious ZIP file to all contacts in the victim's address book, facilitating rapid spread. This results in many accounts being suspended or banned for violating WhatsApp’s terms of service.

The SORVEPOTEL campaign highlights the potential of messaging platforms as vectors for malware distribution. Organizations are advised to implement strong phishing defenses, disable automatic execution of LNK files where feasible, and monitor for unusual WhatsApp Web session activities. While the current focus is on infection rather than data theft, there is potential for future escalation.

Advertisement

Employee training is vital to ensure caution when handling attachments received via messaging apps. It is recommended to maintain updated endpoint security solutions and apply least-privilege principles.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories