WhatsApp Exploited to Spread SORVEPOTEL Malware on Windows Systems
An ongoing malware campaign identified as SORVEPOTEL is targeting Windows systems through WhatsApp messages, primarily affecting users in Brazil. This malware is designed to spread rapidly rather than steal data or demand ransomware payments, leveraging…
An ongoing malware campaign identified as SORVEPOTEL is targeting Windows systems through WhatsApp messages, primarily affecting users in Brazil. This malware is designed to spread rapidly rather than steal data or demand ransomware payments, leveraging social engineering and automation techniques.
According to Trend Research telemetry, the majority of the 477 identified infections are located in Brazil, impacting government, public service, manufacturing, technology, education, and construction sectors. The infection process begins when a user receives a phishing message on WhatsApp from a compromised contact. These messages, written in Portuguese, often include a ZIP archive that appears to be a legitimate document.
In addition to WhatsApp, email has been identified as an alternative vector, with phishing emails distributing similarly named ZIP attachments. Inside these ZIP files is a Windows shortcut (.LNK) file that, when opened, executes a PowerShell or command-line script. This script downloads the primary malware payload from attacker-controlled domains, which are disguised using typo-squatted URLs.
The downloaded payload is typically a batch (.BAT) script that ensures persistence by copying itself into the Windows Startup folder. This script then executes an obfuscated PowerShell command, utilizing Base64 encoding. The script communicates with command-and-control (C&C) servers to download and execute additional in-memory payloads, minimizing forensic traces.
An ongoing malware campaign identified as SORVEPOTEL is targeting Windows systems through WhatsApp messages, primarily affecting users in Brazil.
Despite its sophisticated delivery mechanisms, current campaign activities show no evidence of data exfiltration or file encryption. The focus remains on self-propagation.
SORVEPOTEL detects active WhatsApp Web sessions and automatically forwards the malicious ZIP file to all contacts in the victim's address book, facilitating rapid spread. This results in many accounts being suspended or banned for violating WhatsApp’s terms of service.
The SORVEPOTEL campaign highlights the potential of messaging platforms as vectors for malware distribution. Organizations are advised to implement strong phishing defenses, disable automatic execution of LNK files where feasible, and monitor for unusual WhatsApp Web session activities. While the current focus is on infection rather than data theft, there is potential for future escalation.
Employee training is vital to ensure caution when handling attachments received via messaging apps. It is recommended to maintain updated endpoint security solutions and apply least-privilege principles.
Based on reporting by GBHackers.
