Maverick is a Windows-focused Brazilian banking trojan, first observed in 2024, that targets online banking, cryptocurrency, and payment services. It is associated with the Brazilian cybercrime cluster Water Saci and is considered related to the Coyote and SORVEPOTEL ecosystem, sharing implementation and encryption characteristics while remaining a distinct malware family. Maverick is typically distributed through WhatsApp-based social-engineering campaigns, including worm-like propagation from compromised WhatsApp Web sessions to victims’ contacts. Observed infection chains use archive-contained shortcut payloads, PowerShell, in-memory .NET loading, and encrypted shellcode to minimize disk artifacts. The malware geofences victims for Brazil using locale, regional, timezone, and date-format checks. It monitors supported browsers for visits to targeted Brazilian financial institutions and cryptocurrency exchanges, then can activate credential-harvesting overlays and remote operator functionality. Supported actions include keylogging, screenshot capture, mouse and keyboard control, screen blocking, process manipulation, browser monitoring, and phishing-window generation. Maverick also uses WhatsApp Web automation to propagate malicious messages through authenticated victim accounts. Persistence has been implemented through user-startup execution mechanisms.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The malware family is assessed to be a major update of the Maverick, which is known to leverage a worm called SORVEPOTEL to spread via WhatsApp Web to a victim's contacts.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
This threat group employs a wider-ranging attack model focused on a bespoke delivery and propagation mechanism that includes WhatsApp, ClickFix techniques, and email-centric phishing.
The target field of the LNK file contained an obfuscated Windows command that constructed and ran an initial Base64-encoded PowerShell command.
The archive contained a malicious Windows LNK file that, when launched, initiated a series of malicious PowerShell commands. | The campaign ... seeks to trick users into executing a malicious file attached to a self-spreading message received from a previously infected WhatsApp web session.
The target field of the LNK file contained an obfuscated Windows command that constructed and ran an initial Base64-encoded PowerShell command.
Other notable actors included Coyote and emerging families like Maverick, which abused WhatsApp for distribution while maintaining fileless techniques and overlaps with established Brazilian banking malware to steal credentials and enable fraudulent transactions on desktop banking platforms.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
21 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Older malware family referenced as a predecessor or related family to TCLBANKER.
Brazilian banking trojan family assessed as the predecessor or basis for TCLBANKER. It is known to use the SORVEPOTEL worm for propagation via WhatsApp Web.
A prior Latin American banking-trojan family assessed in the report as the lineage from which TCLBANKER is a major update.
Previously known LATAM/Brazilian banking trojan family assessed in the report as the predecessor or earlier family from which TCLBANKER is a major update.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.