SORVEPOTEL is a Brazil-focused Windows malware family best known as a self-propagating WhatsApp worm used in the Water Saci campaign and related banking-trojan operations. It abuses authenticated WhatsApp Web sessions on infected systems to automate large-scale message delivery to a victim’s contacts and group chats, turning trusted accounts into propagation channels. Multiple observed variants use browser automation frameworks and WhatsApp Web APIs to harvest contacts, reuse existing session artifacts without requiring fresh QR-code authentication, and send lure messages with malicious attachments at scale. The malware has also been described as a conduit or propagation module for downstream Brazilian banking malware including Maverick-family payloads, Astaroth/Guildma, Eternidade Stealer, and the later TCLBANKER ecosystem evolution.
Observed infection chains commonly begin with social-engineering lures delivered through WhatsApp messages from compromised contacts, often using ZIP attachments and desktop-oriented instructions intended to push execution on Windows hosts. Some reporting also describes parallel delivery through phishing email. Across variants, execution has involved obfuscated script loaders, batch files, PowerShell, Python-based automation, MSI packages, and AutoIt components. SORVEPOTEL establishes or supports persistence on Windows and can coordinate follow-on stages that profile the host, identify Brazilian Portuguese environments, inspect browser activity, and selectively activate banking fraud functionality when victims access targeted financial or cryptocurrency services.
A defining capability is session hijacking or session reuse against WhatsApp Web. Implementations have used Selenium, ChromeDriver, and related tooling to clone or access browser session data from Chrome, Edge, and Firefox profiles, launch automated browser instances, enumerate contacts, and transmit malicious files directly through the victim’s authenticated account. Some variants also report contact lists and delivery telemetry back to attacker infrastructure and support operator-controlled pause/resume logic for coordinated propagation. In more advanced campaign chains associated with Brazilian banking malware, companion components have performed anti-analysis checks, security-product discovery, browser monitoring, credential theft, keylogging, process injection, and in-memory loading of banking trojans.
Targeting has been concentrated overwhelmingly in Brazil, with impacts reported across government, public service, manufacturing, technology, education, construction, and enterprise environments. The malware’s lures, locale checks, and targeted financial themes indicate a strong focus on Brazilian users and institutions, especially banks, fintech services, and cryptocurrency platforms. SORVEPOTEL is notable less for standalone destructive effects than for combining worm-like propagation, trusted-account abuse, and delivery of financially motivated payloads within the broader Brazilian banking-malware ecosystem.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"...a worm that propagates via WhatsApp Web known as SORVEPOTEL, which then acts as a conduit for Maverick..."
27 distinct techniques documented for this family, organized by ATT&CK tactic.
The script drops a .bat script which downloads and installs Python.zip, ChromeDriver.exe and PIP
It starts with a Phishing email with a ZIP archived malicious VBS script file.
This variant uses a Python script for malware distribution along with a Banking Trojan.
AutoIt Script contains an infinite loop that monitors the active windows and decides when to execute the malicious payload by scanning all visible window title strings
If it still finds nothing, It looks for program display names that contain keywords of AV program names in the Windows “Uninstall” registry keys.
System information like Computer name, OS info, Username, Local IP, External IP, Current Timestamp, AntiVirus Products, Windows Edition/Version, Processor Name, Total RAM, Logon Domain
System information like Computer name, OS info, Username, Local IP, External IP, Current Timestamp, AntiVirus Products, Windows Edition/Version, Processor Name, Total RAM, Logon Domain, Brazilian banking sites visited are sent to the attacker’s server.
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Older malware family referenced as a predecessor or related family to TCLBANKER.
Worm used to spread Maverick-like banking trojan activity via WhatsApp Web by hijacking authenticated sessions and sending messages to contacts.
WhatsApp-distributed worm abusing previously authenticated chats to send malicious lures, leading to multi-stage infection chains that can culminate in deployment of banking malware (including in-memory Astaroth).
Python-based worm and WhatsApp automation tool that hijacks authenticated WhatsApp Web sessions, scrapes contacts, and propagates itself by sending malicious lures through existing chat threads. It enables lateral spread and acts as the initial access and delivery mechanism for further payloads.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.