216.73.217.22

Unraveling Water Saci's New Multi-Format, AI-Enhanced Attacks Propagated via WhatsApp

· Published 02/12/2025 14:44 · Modified 21/12/2025 18:21

Export JSON

Essential information

Published
02/12/2025 14:44
Modified
21/12/2025 18:21
Tags
2025-12-02 ai-enhanced anti-sandbox backdoor banking trojan brazil casbaneiro metamorfo multi-format attacks powershell python whatsapp
Related entities
18 observables, 1 intrusion sets (apt), 18 techniques (mitre), 2 malware, 5 others

Description

The Water Saci campaign in is using advanced techniques to deliver banking trojans through . The attack chain involves various file formats and scripting languages, designed to bypass detection and increase analysis complexity. Attackers have transitioned from to for their propagation routine, suggesting an accelerated development pipeline. Evidence indicates the possible use of AI tools like LLMs to convert malware scripts. The campaign showcases multi-format malware delivery, aggressive measures, and extensive capabilities. The malware targets Brazilian banking applications and cryptocurrency platforms, using sophisticated techniques for persistence and evasion.

External references