Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

WhatsApp Worm Targets Users with Banking Malware, Steals Login Information

## New Malware Campaign Targets WhatsApp Users in Brazil

New Malware Campaign Targets WhatsApp Users in Brazil

Cybersecurity researchers have uncovered a sophisticated campaign targeting WhatsApp users in Brazil. The malware is designed to steal banking credentials and cryptocurrency exchange login information.

The attack, first detected on Mon, Sep 29, 2025, involves social engineering tactics that exploit users' trust in familiar contacts to disseminate malicious payloads across messaging networks.

The campaign initiates when victims receive seemingly legitimate messages from previously infected WhatsApp contacts via the web-based version of the messaging platform. These messages contain ZIP archives with names such as "NEW-20251001_150505-XXX_XXXXXXX.zip" or employ Portuguese terms like "ORCAMENTO" (Budget) and "COMPROVANTE" (Voucher) to appear credible.

The messages instruct recipients that the content can only be viewed on a computer, directing them away from mobile devices where security protections might be stronger. Upon download, the ZIP file contains a malicious Windows LNK file that triggers a multi-stage PowerShell infection process.

Security researchers at Sophos have detected this initial PowerShell activity in over 400 customer environments, affecting more than 1,000 endpoints.

Cybersecurity researchers have uncovered a sophisticated campaign targeting WhatsApp users in Brazil.
Stephen Gale · Thehackingpost

Impact on Brazilian Financial Institutions

The second-stage PowerShell commands aim to disable critical security defenses, with Portuguese comments indicating intentions to "add an exclusion in Microsoft Defender " and "disable UAC" (User Account Control).

This defense evasion facilitates the deployment of either a Selenium browser automation tool for session hijacking or a banking trojan called Maverick, which specifically monitors connections to Brazilian banks and cryptocurrency exchanges. Upon accessing targeted financial websites, the malware installs a .NET banking trojan to steal login credentials and facilitate unauthorized transactions.

This payload's sophistication suggests significant development resources and detailed knowledge of Brazilian banking systems.

The campaign's self-propagating nature is particularly concerning. After infection, the malware attempts to spread to the victim's WhatsApp contacts, creating an exponential distribution network that leverages social trust. This worm-like behavior significantly amplifies the campaign's reach and effectiveness.

Advertisement

Security experts emphasize that this attack demonstrates the evolving threat landscape, where cybercriminals increasingly target messaging platforms and social media channels. The use of WhatsApp Web allows attackers to bypass mobile security measures while exploiting the platform's widespread adoption in Brazil.

Organizations and individuals can protect themselves by educating users about the risks of opening suspicious attachments, even from known contacts. Rapid response to PowerShell execution alerts can help contain infections in early stages, while maintaining updated endpoint security solutions provides crucial defense against these sophisticated multi-stage attacks.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories