Water Saci, also referred to as Augmented Marauder, is a Brazil-based cybercrime threat cluster focused on banking fraud and credential theft, with operations centered on Latin American financial targets. The actor is best known for wormable campaigns that abuse trusted communication channels—especially WhatsApp Web and, in some operations, email accounts—to propagate banking malware through victims’ own contacts. Activity attributed to Water Saci has been linked to the Maverick ecosystem and associated WhatsApp-propagating components such as SORVEPOTEL, and separate campaigns have delivered banking trojans including Casbaneiro, Astaroth, and newer Maverick-derived malware such as TCLBANKER. Reporting also notes possible ties to the Coyote banking malware ecosystem, although overlap does not conclusively establish common operators. Water Saci primarily targets users in Brazil, with additional campaigns aimed at Spanish-speaking victims across Latin America and Spain. Its targeting is heavily concentrated on banks, fintech services, payment platforms, and cryptocurrency services. The actor commonly uses phishing and social engineering themes tailored to local trust relationships, including malicious attachments sent through hijacked WhatsApp Web sessions and self-propagating email lures sent from compromised Outlook or other mail accounts. Campaigns have used layered delivery chains involving HTA, VBS, ZIP, PDF, MSI, PowerShell, Python, AutoIt, and DLL side-loading to complicate analysis and evade simple detection. Observed capabilities include initial access through phishing and malicious attachments; session hijacking of authenticated WhatsApp Web sessions; credential theft through banking overlays and keylogging; persistence via scheduled tasks and registry changes; defense evasion through anti-debugging, anti-VM checks, locale gating, ETW disabling, hook removal, and multi-stage loaders; process injection and process hollowing into legitimate Windows processes; reconnaissance and victim profiling focused on Brazilian Portuguese environments, installed security tools, browser activity, and targeted financial websites; exfiltration of system, contact, and victim activity data; and post-compromise remote control functions such as command execution, screen capture, screen streaming, clipboard manipulation, file operations, and window monitoring. Water Saci’s malware frequently monitors browser URLs or active windows for banking, payment, and cryptocurrency activity before triggering overlays or operator interaction. The group’s operations show sustained iterative development, including migration from PowerShell-based propagation to Python automation and the use of tooling that improves browser compatibility, campaign orchestration, and large-scale message delivery.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
23 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Threat cluster attributed with the Maverick banking trojan campaign, which is known to use the SORVEPOTEL worm to spread via WhatsApp Web to victims' contacts.
Financially motivated Brazilian cybercrime operation conducting banking-Trojan campaigns targeting Spanish-speaking users across Latin America and Spain via phishing emails and WhatsApp, using self-propagation to steal banking credentials.
Brazil-focused financially motivated actor evolving a multi-stage infection chain to spread a banking trojan via WhatsApp (including worm-like propagation), using layered file formats and shifting scripting languages to improve evasion and scale.
Brazil-focused financially motivated actor using WhatsApp worming and layered infection chains (HTA/PDF; Python variant) to deploy banking trojans and enable fraud (including RelayNFC mentioned in title).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.