New Banking Trojan Identified, Distributed Through WhatsApp
Essential information
- Published
- 20/11/2025 02:17
- Modified
- 21/11/2025 01:29
- Tags
- 2025-11-20 banking trojan brazil credential-theft delphi eternidade stealer imap social engineering whatsapp
- Related entities
- 1 vulnerabilities (cve), 23 observables, 20 techniques (mitre), 1 malware, 3 others
Description
A new banking Trojan dubbed Eternidade Stealer has been identified, distributed through WhatsApp hijacking and social engineering. The malware, written in Delphi, uses IMAP to retrieve C2 addresses dynamically. It's spread via a WhatsApp worm campaign using a Python script. The attack chain involves an obfuscated VBScript, a batch file, and an MSI installer deploying the Trojan. Eternidade Stealer targets Brazilian victims, checks for specific banking and cryptocurrency applications, and uses sophisticated techniques for credential harvesting and maintaining persistence. The malware communicates with its C2 server using encrypted commands and can deploy fake overlays to steal banking information.