Water Saci is a Brazilian-focused malware campaign associated with banking-trojan activity and WhatsApp-based self-propagation. The operation has evolved from simpler phishing-style delivery into layered social-engineering chains that abuse trusted messaging relationships, especially through WhatsApp, to distribute malicious archives, script-based launchers, and MSI installers. Reporting links the campaign to a Python-based WhatsApp worm used to harvest contacts, send personalized lure messages, and forward malicious attachments to additional victims, enabling worm-like spread across user contact networks.
The campaign targets Windows systems and is heavily localized for Brazilian victims, including checks for Brazilian Portuguese environments and monitoring for Brazilian banks, payment services, fintech platforms, and cryptocurrency exchanges and wallets. Observed payload chains include script and installer stages that deploy Delphi-based banker or stealer components, perform host profiling, enumerate security products, and use anti-analysis and evasion measures. Documented functionality includes credential theft through banking overlays, active-window monitoring, contact theft, exfiltration of host and victim data, persistence, and process injection or hollowing into legitimate processes. Some reporting also notes dynamic command-and-control retrieval via IMAP and continued malware development across 2025.
Water Saci is notable for incorporating AI-assisted code conversion, with operators reportedly using large language models to help migrate earlier PowerShell propagation logic to Python, improving automation, compatibility, and operational flexibility. The campaign is primarily aimed at Brazilian financial institutions and cryptocurrency users, with potential spillover risk to other Latin American targets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Water Saci Campaign Uses LLMs to Convert Malware to Python, Spreads Banking Trojan Via WhatsApp Worm
Water Saci is a self-propagating malware campaign targeting financial institutions and cryptocurrency exchanges, primarily in Brazil. It uses WhatsApp to spread malicious files, employs advanced social engineering, and leverages AI to enhance its propagation and evasion capabilities. The malware steals data, monitors user desktop activity, and is designed to bypass traditional security defenses.
A named banking trojan/campaign referenced as part of the evolution of WhatsApp-based malware distribution in Brazil.
Mentioned as a prior campaign in Brazil’s cybercrime ecosystem for contextual comparison to the current Eternidade activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.