Researchers reported a Brazil-focused malware campaign that hijacks WhatsApp Web sessions to spread a malicious ZIP archive and deploy the Eternidade Stealer banking trojan. The infection chain uses an obfuscated VBScript downloader, an MSI dropper, an AutoIt loader, and a final Delphi-based payload, while a parallel Python-based worm installs Selenium and ChromeDriver to steal contacts and automatically send phishing messages to the victim’s WhatsApp contacts. The malware is heavily localized, checking for Portuguese (Brazil) language settings and focusing on Brazilian banks, fintech services, and cryptocurrency platforms.
Once installed, the malware profiles the host, enumerates security products, monitors browser history and banking activity, and uses overlays and credential theft when targeted financial services are detected. Analysts said later stages are decrypted and loaded in memory, including reflective loading and process hollowing into svchost.exe, while command-and-control relies on attacker infrastructure including a PHP server, 013net.com.br, and IMAP over SSL with hardcoded email credentials to retrieve updated infrastructure, with a fallback domain if that fails. The campaign, also tracked as a Water-Saci/SorvePotel variant and compared with older Brazilian banking trojans such as Casbaneiro, shows an evolving effort to combine messaging-platform worming with banking fraud and credential theft.

Pull IOCs and campaign context straight into your stack.
4 events from the most recent confirmed update back to the earliest known activity.
SpiderLabs identified older samples similar to the Eternidade/WhatsApp campaign from January 2025, indicating the actor had been developing this malware set before the later reports.
ISH Tecnologia published an analysis of the WhatsWorm campaign, describing WhatsApp-delivered ZIP lures, a VBS downloader, MSI and AutoIT stages, and a final Delphi-based Eternidade Stealer payload. The report also disclosed specific infrastructure, runtime string decryption details, and hardcoded IMAP email credentials used for C2.
K7 Labs reported a Brazil-focused phishing campaign it described as a Water-Saci variant using the SorvePotel malware family. The report detailed a ZIP/VBS infection chain, WhatsApp Web abuse via Selenium and injected JavaScript, and an MSI-delivered banking trojan that loads in memory and injects into svchost.
LevelBlue SpiderLabs reported a Brazilian banking and credential-stealing campaign using a Delphi malware family it named Eternidade Stealer, distributed through WhatsApp hijacking and social engineering. The analysis described a VBScript-to-MSI infection chain, a Python WhatsApp worm, and IMAP-based C2 retrieval.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 43 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
4 references tracked. Mallory keeps watching after this page renders.
ish.com.br
Open sourcelabs.k7computing.com
Open sourcelevelblue.com
Open sourcewelivesecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.