216.73.217.22

New Banking Trojan Identified, Distributed Through WhatsApp

· Published 20/11/2025 02:17 · Modified 21/11/2025 01:29

Export JSON

Essential information

Published
20/11/2025 02:17
Modified
21/11/2025 01:29
Tags
2025-11-20 banking trojan brazil credential-theft delphi eternidade stealer imap social engineering whatsapp
Related entities
1 vulnerabilities (cve), 23 observables, 20 techniques (mitre), 1 malware, 3 others

Description

A new dubbed has been identified, distributed through hijacking and . The malware, written in , uses to retrieve C2 addresses dynamically. It's spread via a worm campaign using a Python script. The attack chain involves an obfuscated VBScript, a batch file, and an MSI installer deploying the Trojan. targets Brazilian victims, checks for specific banking and cryptocurrency applications, and uses sophisticated techniques for credential harvesting and maintaining persistence. The malware communicates with its C2 server using encrypted commands and can deploy fake overlays to steal banking information.

External references