216.73.216.6

Brazilian Campaign: Spreading the Malware via WhatsApp

· Published 24/11/2025 12:02 · Modified 21/12/2025 17:59

Export JSON

Essential information

Published
24/11/2025 12:02
Modified
21/12/2025 17:59
Tags
2025-11-24 autoit banking trojan brazil in-memory execution phishing selenium sorvepotel water saci whatsapp
Related entities
4 observables, 20 techniques (mitre), 2 malware, 3 others

Description

A massive campaign targeting is spreading malware through Web using an open-source automation script and loading a into memory. The attack begins with a email containing a malicious VBS script that downloads and executes an MSI file and another VBS file. The second VBS installs Python and , which are used to inject malicious JavaScript into Web. This allows the malware to send itself to the victim's contacts. The MSI file drops an script that monitors for Brazilian banking and cryptocurrency-related windows, then loads an encrypted payload into memory to avoid detection. The payload targets specific Brazilian financial institutions and cryptocurrency wallets.

External references