Brazilian Campaign: Spreading the Malware via WhatsApp
Essential information
- Published
- 24/11/2025 12:02
- Modified
- 21/12/2025 17:59
- Tags
- 2025-11-24 autoit banking trojan brazil in-memory execution phishing selenium sorvepotel water saci whatsapp
- Related entities
- 4 observables, 20 techniques (mitre), 2 malware, 3 others
Description
A massive phishing campaign targeting Brazil is spreading malware through WhatsApp Web using an open-source automation script and loading a banking trojan into memory. The attack begins with a phishing email containing a malicious VBS script that downloads and executes an MSI file and another VBS file. The second VBS installs Python and Selenium, which are used to inject malicious JavaScript into WhatsApp Web. This allows the malware to send itself to the victim's contacts. The MSI file drops an AutoIt script that monitors for Brazilian banking and cryptocurrency-related windows, then loads an encrypted payload into memory to avoid detection. The payload targets specific Brazilian financial institutions and cryptocurrency wallets.