Maverick is a Brazilian banking trojan first reported in 2024 and active in 2025, primarily targeting users in Brazil. It is commonly referred to as Maverick or MaverickBanker and is assessed by multiple researchers as a distinct malware family with significant code and technique overlap with the Brazilian banking trojan Coyote; some reporting further assesses it as an evolution of Coyote. Maverick is also described as part of the MAVERICK/SORVEPOTEL family, with later malware such as TCLBANKER assessed as a major update of the Maverick and SORVEPOTEL ecosystem.
Its most notable infection and propagation vector is WhatsApp. Campaigns used WhatsApp messages sent from previously infected or hijacked WhatsApp Web sessions to deliver ZIP archives containing malicious Windows LNK files. The LNK files launched obfuscated cmd.exe and PowerShell-based multi-stage infection chains that were described as modular, largely fileless, and reliant on in-memory .NET assembly loading and Donut-encrypted shellcode. Maverick propagation modules used Selenium and the open-source WPPConnect project to automate WhatsApp Web, hijack authenticated sessions, harvest contacts, and send malicious messages or attachments to victims’ contacts in a worm-like manner. Reporting also links Water Saci to dissemination of Maverick via WhatsApp Web.
Maverick geofences victims to Brazil and may self-terminate or refuse installation outside the country. Reported checks include timezone, language or locale, region, and date format. Once active, Maverick monitors browser sessions and active tabs for access to targeted Brazilian financial services. Reported targeting includes 26 Brazilian bank websites, six cryptocurrency exchange websites, and one payment platform; other reporting describes monitoring of URLs associated with Brazilian banks and cryptocurrency exchanges. When a targeted financial domain is detected, Maverick can install or activate a feature-rich .NET banking trojan component.
Observed capabilities include browser monitoring, credential theft, phishing overlays, keylogging, screenshot capture, mouse control, screen blocking during banking access, process termination, and remote-interaction style command handling. One report states the implant monitored active browser sessions and, upon matching a target financial domain, installed a subsequent .NET banking trojan. The malware used UI Automation to inspect browser activity, and reporting describes compressed and AES-256-encrypted target lists similar to Coyote’s implementation. Agent communications were reported over WatsonTCP with SSL using an encrypted local X.509 certificate, and supported commands included INFOCLIENT, SCREENSHOT, KEYLOGGER, REBOOT, process and window manipulation, remote mouse and keyboard interaction, and phishing window generation.
Associated infrastructure and indicators directly mentioned in reporting include sorvetenopote[.]com, casadecampoamazonas[.]com, expansiveuser[.]com, and zapgrande[.]com. One observed API URL was hxxps://sorvetenopote.com/api/v1/3d045ada0df942c983635e. Reported detections include HEUR:Trojan.Multi.Powenot.a and HEUR:Trojan-Banker.MSIL.Maverick.gen. Kaspersky reported blocking about 62,000 infection attempts in Brazil in the first 10 days of October 2025.
Maverick has been associated in reporting with Brazilian cybercrime activity and with the Water Saci cluster’s WhatsApp-based distribution tradecraft. It targets desktop banking activity in Brazil and has been highlighted as a notable Brazilian banking malware family active in 2025.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The malware family is assessed to be a major update of the Maverick, which is known to leverage a worm called SORVEPOTEL to spread via WhatsApp Web to a victim's contacts.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
This threat group employs a wider-ranging attack model focused on a bespoke delivery and propagation mechanism that includes WhatsApp, ClickFix techniques, and email-centric phishing.
The target field of the LNK file contained an obfuscated Windows command that constructed and ran an initial Base64-encoded PowerShell command.
The archive contained a malicious Windows LNK file that, when launched, initiated a series of malicious PowerShell commands. | The campaign ... seeks to trick users into executing a malicious file attached to a self-spreading message received from a previously infected WhatsApp web session.
The target field of the LNK file contained an obfuscated Windows command that constructed and ran an initial Base64-encoded PowerShell command.
Other notable actors included Coyote and emerging families like Maverick, which abused WhatsApp for distribution while maintaining fileless techniques and overlaps with established Brazilian banking malware to steal credentials and enable fraudulent transactions on desktop banking platforms.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Older malware family referenced as a predecessor or related family to TCLBANKER.
Brazilian banking trojan family assessed as the predecessor or basis for TCLBANKER. It is known to use the SORVEPOTEL worm for propagation via WhatsApp Web.
Previously known LATAM/Brazilian banking trojan family assessed in the report as the predecessor or earlier family from which TCLBANKER is a major update.
Emerging Brazilian banking malware distributed via WhatsApp, using fileless techniques to steal credentials and facilitate fraudulent transactions on desktop banking platforms.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.