Maverick.StageTwo is a Windows .NET malware payload used in the Brazil-focused Water Saci intrusion cluster and delivered by the WhatsApp-propagating SORVEPOTEL infection chain. It is associated with financially motivated activity targeting Brazilian and broader Latin American banking and cryptocurrency users. The malware is deployed after an initial phishing infection that uses ZIP archives containing malicious shortcut files, which launch PowerShell-based loaders and in-memory .NET components.
Maverick.StageTwo functions as an intermediate surveillance and targeting component within a multi-stage banking malware workflow. It monitors active browser windows, extracts visited URLs, and checks them against a hardcoded list of financial and cryptocurrency services, including institutions popular in Brazil. It also contains logic to identify at least one bank-specific browser environment. When a targeted site is detected, it decrypts and loads an additional .NET payload, Maverick.Agent, directly in memory.
Within this broader chain, the malware supports credential theft and banking fraud operations by enabling delivery of follow-on components that perform screenshot capture, keylogging, fake banking overlays, and collection of authentication material such as credentials, electronic signatures, and QR-code-based verification data. The surrounding loader infrastructure uses anti-analysis checks, in-memory execution, and process injection to evade detection. Campaign activity has been concentrated in Brazil, with notable impact on government and public service organizations as well as manufacturing, technology, education, and construction sectors.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
One of the retrieved payloads is a .NET executable, which is referred to as Maverick.StageTwo, as indicated by the strings found within the binary.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A .NET payload delivered by SORVEPOTEL that persists via BAT file creation, monitors active browser URLs, checks for targeted Brazilian banking domains, and loads additional credential-stealing functionality in memory.
Secondary payload delivered by Sorvepotel to steal banking information (credential theft and related banking fraud functionality).
Secondary payload delivered by Sorvepotel to steal banking information (credential theft and related banking fraud functionality).
Maverick.StageTwo is a secondary payload delivered by Sorvepotel, targeting Brazilian banking users to gather banking information.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.