Maverick.Agent is a Windows-based .NET banking malware component used in the Water Saci campaign, which is centered on the WhatsApp-propagated SORVEPOTEL infection chain and has been observed primarily in Brazil. It is deployed as a later-stage payload after initial compromise through phishing messages or emails carrying ZIP archives with malicious shortcut files, and is loaded in memory when the malware detects that the victim is visiting targeted banking or cryptocurrency services. The malware appears tailored for Brazilian victims, performing locale, timezone, region, and date-format checks before activating.
Maverick.Agent combines spyware, credential theft, and banking-trojan-style social engineering functions. It can collect system information, capture screenshots, log keystrokes, manipulate processes and windows, and inject mouse and keyboard input. A notable feature is its use of fake overlay windows and full-screen locking dialogs that imitate legitimate financial institutions in order to steal credentials, electronic signatures, and QR-code-based authentication data. It is associated with targeting Brazilian and Latin American financial institutions and cryptocurrency platforms. Within the broader intrusion chain, related components also monitor browser activity and support WhatsApp Web abuse for rapid propagation, while Maverick.Agent itself serves as the credential-stealing and fraudulent overlay stage of the operation.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The subsequent payload is a .NET executable known as Maverick.Agent, which exhibits information and credential stealing capabilities, as evidenced by the public classes contained within the .NET binary.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
It runs in hidden mode (- w hidden ) to evade user notice and leverages the encoded command (- enc ) feature for additional payload obfuscation.
Specifically, it harvests: Computer Name Operating System Name and Version MAC Address OS Architecture Malware Version Number of Monitors Attached
it implements anti-analysis measures by scanning for specific process names commonly associated with debugging or reverse engineering tools. If any of the following processes are detected, the DLL will terminate itself to evade analysis.
If any of the following processes are detected, the DLL will terminate itself to evade analysis. apimonitor burp fiddler ghidra ida immunity ollydebug windbg wireshark x64debug
it establishes a C&C communication channel ... and subsequently instantiates a WatsonClient that connects to the malicious server " adoblesecuryt[.]com " over port 443 (HTTPS).
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A follow-on .NET banking trojan and backdoor that validates Brazilian geolocation, connects to C2, steals system and credential data, logs keystrokes, captures screenshots, manipulates windows, and presents fake banking overlays to harvest sensitive information and authentication tokens.
Banking-focused payload capable of credential theft and presenting fake overlay pages to mimic banking sites for fraud.
Banking-focused payload capable of credential theft and presenting fake overlay pages to mimic banking sites for fraud.
Maverick.Agent is a credential-stealing malware capable of displaying fake overlay windows that mimic legitimate financial websites to trick users into revealing sensitive information. It is delivered as a related payload in the Sorvepotel campaign.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.