Coyote is a Brazil-focused cybercrime malware ecosystem associated with WhatsApp-centric propagation and credential or session abuse to spread malicious payloads through victims’ contact networks. It has been linked by researchers to closely related activity clusters such as Water Saci, although that relationship has been assessed as similarity or likely linkage rather than definitive identity. The ecosystem is notable for abusing hijacked WhatsApp Web sessions to automate mass messaging, distribute malicious archives, and propagate laterally through trusted social contacts and group chats. Observed tradecraft associated with the broader Coyote-linked activity includes script- and PowerShell-based loaders, in-memory execution, browser automation through Chrome and Selenium, theft and reuse of browser profile data and authenticated session material, harvesting of WhatsApp contacts, and exfiltration of victim and campaign telemetry to attacker-controlled infrastructure. Operators have used remote campaign management features to pause or resume propagation across infected hosts, indicating coordinated multi-host operations. Persistence has been established through scheduled tasks and registry-based mechanisms, while defense evasion has included locale gating focused on Portuguese-language systems, anti-debugging and anti-analysis checks, and self-deletion behavior. The activity is consistent with financially motivated Brazilian cybercrime operations that prioritize scalable social-messaging propagation and post-compromise automation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.