SORVEPOTEL is a Brazil-focused Windows malware family best known as a self-propagating WhatsApp worm used in the Water Saci campaign. It abuses authenticated WhatsApp Web sessions on infected systems to automatically send malicious attachments and lure messages to the victim’s contacts and group chats, enabling rapid worm-like spread through trusted social relationships. Observed variants use browser automation frameworks and WhatsApp Web scripting to hijack or reuse existing sessions, enumerate contacts, and distribute payloads at scale, often causing compromised accounts to be suspended for spam-like behavior.
Infection chains associated with SORVEPOTEL commonly rely on social-engineering lures delivered through WhatsApp messages from compromised contacts, and in some cases phishing emails, typically using archive files that contain script or shortcut-based launchers. These launchers invoke PowerShell, batch, Visual Basic Script, HTA, Python, MSI, AutoIt, or .NET components to download or unpack additional stages, establish persistence, and execute payloads in memory. Multiple reports describe anti-analysis and geofencing logic focused on Brazilian victims, including checks for Portuguese (Brazil) language settings, local banking software, browser history related to Brazilian financial institutions, security tools, debuggers, and virtualized environments.
Beyond propagation, SORVEPOTEL has been used as a delivery and access mechanism for banking-trojan and spyware functionality targeting Brazilian banks, payment services, and cryptocurrency platforms. Associated payload chains have included capabilities such as browser and URL monitoring, credential theft, keylogging, screenshot capture, fake banking overlays, remote command execution, process injection, and broader host profiling. Several analyses link SORVEPOTEL operationally and technically to the Maverick banking malware ecosystem and the Water Saci cluster, with later campaign evolution also tied to newer Brazilian banking-trojan activity such as TCLBANKER. The malware has disproportionately affected organizations in Brazil, including government and public-service entities, while also impacting manufacturing, technology, education, and construction sectors.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
As observed in our previously published research on the SORVEPOTEL malware and the broader Water Saci campaign, this popular platform has been used to launch sophisticated campaigns.
35 distinct techniques documented for this family, organized by ATT&CK tactic.
SORVEPOTEL has been observed to spread across Windows systems through convincing phishing messages with malicious ZIP file attachments.
When the LNK file is executed, this shortcut covertly launches a command-line or PowerShell script that downloads the primary malware payload from attacker-controlled domains.
The decrypted command retrieves a malicious script from a specified URL and executes it in memory using the Invoke-Expression (IEX) function.
The script drops a .bat script which downloads and installs Python.zip, ChromeDriver.exe and PIP
It starts with a Phishing email with a ZIP archived malicious VBS script file.
This variant uses a Python script for malware distribution along with a Banking Trojan.
The Selenium Chrome driver is used to inject a malicious JS code in WhatsApp Web.
the .NET DLL decrypts and subsequently injects into separate instances of suspended powershell_ise.exe processes it creates
the .NET DLL decrypts and subsequently injects into separate instances of suspended powershell_ise.exe processes it creates
It runs in hidden mode (- w hidden ) to evade user notice and leverages the encoded command (- enc ) feature for additional payload obfuscation.
The message has a ZIP archive attachment, bearing the name "RES-20250930_112057.zip,” or "ORCAMENTO_114418.zip," or something similarly disguised as a benign document, such as a receipt, budget, or health app-related file.
the .NET DLL decrypts and subsequently injects into separate instances of suspended powershell_ise.exe processes it creates
the .NET DLL decrypts and subsequently injects into separate instances of suspended powershell_ise.exe processes it creates
it implements anti-analysis measures by scanning for specific process names commonly associated with debugging or reverse engineering tools. If any of the following processes are detected, the DLL will terminate itself to evade analysis.
AutoIt Script contains an infinite loop that monitors the active windows and decides when to execute the malicious payload by scanning all visible window title strings
If it still finds nothing, It looks for program display names that contain keywords of AV program names in the Windows “Uninstall” registry keys.
System information like Computer name, OS info, Username, Local IP, External IP, Current Timestamp, AntiVirus Products, Windows Edition/Version, Processor Name, Total RAM, Logon Domain
It then looks for common security apps used by Brazilian banks by checking if certain folders exist on the C: drive
it implements anti-analysis measures by scanning for specific process names commonly associated with debugging or reverse engineering tools. If any of the following processes are detected, the DLL will terminate itself to evade analysis.
System information like Computer name, OS info, Username, Local IP, External IP, Current Timestamp, AntiVirus Products, Windows Edition/Version, Processor Name, Total RAM, Logon Domain, Brazilian banking sites visited are sent to the attacker’s server.
it establishes a C&C communication channel ... and subsequently instantiates a WatsonClient that connects to the malicious server " adoblesecuryt[.]com " over port 443 (HTTPS).
it establishes a C&C communication channel ... and subsequently instantiates a WatsonClient that connects to the malicious server " adoblesecuryt[.]com " over port 443 (HTTPS).
30 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
21 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A banking trojan previously linked to WhatsApp-delivered campaigns in Brazil and referenced as prior related research context for the current Water Saci activity.
A Windows malware family used in the Water Saci campaign that spreads via phishing ZIP/LNK attachments and then propagates through hijacked WhatsApp Web sessions. It establishes persistence, downloads staged PowerShell and .NET payloads, monitors banking-related activity, targets Brazilian financial institutions, steals information and credentials through overlay phishing, and supports remote backdoor commands.
Older malware family referenced as a predecessor or related family to TCLBANKER.
Worm used to spread Maverick-like banking trojan activity via WhatsApp Web by hijacking authenticated sessions and sending messages to contacts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.