Water Saci is a Brazilian cybercrime threat cluster focused on banking fraud and malware propagation, primarily targeting users and organizations in Brazil and, in some campaigns, Spanish-speaking victims across Latin America and Spain. The actor is also referred to as Augmented Marauder. It is best known for abusing trusted communication channels—especially WhatsApp and, in some operations, email—to distribute banking trojans and worm-like propagation components. Water Saci has been associated with multiple malware chains and related banking-trojan ecosystems, including SORVEPOTEL, Maverick, Casbaneiro/Metamorfo variants, Horabot, and activity assessed by some researchers as linked to the broader Coyote ecosystem. Its operations commonly rely on phishing and social engineering delivered from compromised accounts, often using ZIP archives, malicious shortcut files, HTA files, Visual Basic Script, batch scripts, MSI installers, PowerShell, Python, AutoIt, and .NET payloads in layered infection chains designed to complicate analysis and evade simple detection. A defining characteristic of Water Saci is automated propagation through hijacked WhatsApp Web sessions. Malware associated with the cluster can detect active authenticated sessions, harvest contacts, and send malicious attachments or messages to contacts and groups at scale using browser automation frameworks and WhatsApp automation libraries. Some campaigns also abused victims’ Outlook or email accounts for self-propagation, increasing trust and reducing the likelihood of filtering. The actor has shown iterative development, including migration from PowerShell-based propagation to Python-based tooling with broader browser support and improved automation. Water Saci’s payloads exhibit strong Brazil-focused victim validation and targeting logic, including checks for Brazilian Portuguese language settings, locale, timezone, regional configuration, and evidence of Brazilian banking software or browsing activity. The malware monitors browser activity and active windows for banking, payment, and cryptocurrency services, then deploys credential-harvesting overlays, fake banking dialogs, keylogging, screenshots, clipboard manipulation, and remote-control features. Reported capabilities include system profiling, command execution, file transfer, process and window management, screen streaming, keyboard and mouse control, and exfiltration of host and victim data. The cluster also demonstrates mature defense-evasion and post-exploitation tradecraft. Observed samples use anti-analysis and anti-debugging checks, anti-virtualization logic, in-memory execution, reflective loading, process injection or process hollowing, persistence via startup mechanisms, registry run keys, and scheduled tasks, as well as fallback command-and-control discovery through IMAP. Some newer malware linked to this ecosystem also used DLL side-loading and telemetry-disabling techniques. Water Saci’s targeting has included government and public service entities, as well as manufacturing, technology, education, construction, financial institutions, and cryptocurrency users. The actor’s dominant objective is financial gain through banking credential theft, account compromise, and fraud, with rapid self-propagation serving as a force multiplier for victim acquisition.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
51 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 malware families attributed to this actor across reporting.
3 additional families tracked in Mallory.
21 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting WhatsApp-delivered malware campaigns in Brazil using multi-stage infection chains with HTA, MSI, AutoIt, and Python-based propagation automation to spread banking trojans, maintain persistence, evade analysis, and target banking and cryptocurrency activity.
A self-propagating malware campaign using WhatsApp phishing messages with malicious ZIP/LNK attachments to infect Windows systems, hijack WhatsApp Web sessions for automated spread, and deploy banking-trojan functionality targeting Brazilian financial institutions.
Threat cluster attributed with the Maverick banking trojan campaign, which is known to use the SORVEPOTEL worm to spread via WhatsApp Web to victims' contacts.
Financially motivated Brazilian cybercrime operation conducting banking-Trojan campaigns targeting Spanish-speaking users across Latin America and Spain via phishing emails and WhatsApp, using self-propagation to steal banking credentials.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.