WhatsApp Worm Targets Users with Banking Malware, Steals Login Information
## New Malware Campaign Targets WhatsApp Users in Brazil
New Malware Campaign Targets WhatsApp Users in Brazil
Cybersecurity researchers have uncovered a sophisticated campaign targeting WhatsApp users in Brazil. The malware is designed to steal banking credentials and cryptocurrency exchange login information.
The attack, first detected on Mon, Sep 29, 2025, involves social engineering tactics that exploit users' trust in familiar contacts to disseminate malicious payloads across messaging networks.
The campaign initiates when victims receive seemingly legitimate messages from previously infected WhatsApp contacts via the web-based version of the messaging platform. These messages contain ZIP archives with names such as "NEW-20251001_150505-XXX_XXXXXXX.zip" or employ Portuguese terms like "ORCAMENTO" (Budget) and "COMPROVANTE" (Voucher) to appear credible.
The messages instruct recipients that the content can only be viewed on a computer, directing them away from mobile devices where security protections might be stronger. Upon download, the ZIP file contains a malicious Windows LNK file that triggers a multi-stage PowerShell infection process.
Security researchers at Sophos have detected this initial PowerShell activity in over 400 customer environments, affecting more than 1,000 endpoints.
Cybersecurity researchers have uncovered a sophisticated campaign targeting WhatsApp users in Brazil.
Impact on Brazilian Financial Institutions
The second-stage PowerShell commands aim to disable critical security defenses, with Portuguese comments indicating intentions to "add an exclusion in Microsoft Defender " and "disable UAC" (User Account Control).
This defense evasion facilitates the deployment of either a Selenium browser automation tool for session hijacking or a banking trojan called Maverick, which specifically monitors connections to Brazilian banks and cryptocurrency exchanges. Upon accessing targeted financial websites, the malware installs a .NET banking trojan to steal login credentials and facilitate unauthorized transactions.
This payload's sophistication suggests significant development resources and detailed knowledge of Brazilian banking systems.
The campaign's self-propagating nature is particularly concerning. After infection, the malware attempts to spread to the victim's WhatsApp contacts, creating an exponential distribution network that leverages social trust. This worm-like behavior significantly amplifies the campaign's reach and effectiveness.
Security experts emphasize that this attack demonstrates the evolving threat landscape, where cybercriminals increasingly target messaging platforms and social media channels. The use of WhatsApp Web allows attackers to bypass mobile security measures while exploiting the platform's widespread adoption in Brazil.
Organizations and individuals can protect themselves by educating users about the risks of opening suspicious attachments, even from known contacts. Rapid response to PowerShell execution alerts can help contain infections in early stages, while maintaining updated endpoint security solutions provides crucial defense against these sophisticated multi-stage attacks.
Based on reporting by GBHackers.
