The Water Saci malware campaign has evolved to leverage WhatsApp as its primary infection vector, distributing malicious ZIP files to contacts and groups from compromised accounts. The latest variant features a multi-layered worm that utilizes IMAP email protocols for covert command-and-control (C2) communications and session hijacking, enabling attackers to maintain persistent access and evade detection. The campaign incorporates advanced anti-analysis techniques and restricts activity to specific targets, making it more resilient and difficult to track.
Researchers have observed that the Water Saci malware now supports real-time remote management, allowing threat actors to orchestrate coordinated botnet operations, gather intelligence, and dynamically control infected endpoints. The campaign's multi-vector persistence mechanisms and sophisticated C2 infrastructure enable attackers to pause, resume, and monitor malware activity across multiple machines. Security vendors have released detection rules and threat intelligence to help organizations defend against this evolving threat.

Get the actors, campaigns, and ATT&CK mapping behind it.
5 events from the most recent confirmed update back to the earliest known activity.
TrendAI reported a new Water Saci campaign in Brazil using WhatsApp-delivered ZIP, fake PDF, and especially HTA lures that launch obfuscated VBScript, download an MSI package, and deploy an AutoIt-based multi-stage banking trojan with persistence, anti-analysis, process hollowing, and extensive backdoor functions. The campaign also uses a Python propagation script, whatsz.py, described as an upgrade of the earlier PowerShell WhatsApp automation component.
Trend Micro assessed that Water Saci likely has ties to the Brazil-focused Coyote ecosystem based on overlapping tactics and the campaign's evolution, while noting that attribution remains unconfirmed.
Researchers reported that the campaign incorporated an email/IMAP-based channel to retrieve C2 URLs, followed by frequent HTTP polling for commands, along with registry and scheduled-task persistence. The updated malware also introduced real-time operator controls, anti-analysis checks, and telemetry-driven coordination across multiple infected hosts.
The Water Saci malware campaign was observed abusing hijacked WhatsApp Web sessions to send malicious ZIP files to victims' contacts and group chats, enabling worm-like propagation through trusted messaging relationships.
A newly observed October 2025 infection chain replaced earlier .NET-based components with an obfuscated VBS downloader and fileless PowerShell payloads executed in memory. The malware used a PowerShell component masquerading as 'WhatsApp Automation v6.0' to automate Chrome/Selenium, steal browser session data, and bypass WhatsApp Web authentication.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
trendaisecurity.com
Open sourcesecurityonline.info
Open sourcetrendmicro.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.