Close Menu
Invest Intellect
    Facebook X (Twitter) Instagram
    Invest Intellect
    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Commodities
    • Cryptocurrency
    • Fintech
    • Investments
    • Precious Metal
    • Property
    • Stock Market
    Invest Intellect
    Home»Fintech»WhatsApp worm using python script targets Brazillian crypto and fintech wallets
    Fintech

    WhatsApp worm using python script targets Brazillian crypto and fintech wallets

    November 20, 20252 Mins Read


    Brazilian cybersecurity researchers from SpiderLabs have reported that a banking trojan, known as “Eternidade Stealer”, is being pushed, leveraging a combination of social engineering and WhatsApp hijacking to target financial data. The malware is geo-targeted; it checks if the device uses, Brazilian Portuguese language in the OS if not, it self-destructs.

    WhatsApp worm + Eternidade Stealer

    The attacker sends a file/links via WhatsApp, mostly via WhatsApp web, such as “fake government programs, delivery notifications,” messages from friends and fraudulent investment groups containing the python-based worm. Once someone opens the file/link, the worm infiltrates the device and delivers a Delphi-based banking trojan Eternidade Stealer. It runs in the background and scans for financial data and logins for a range of Brazilian banks and fintech or crypto exchanges and wallets. On the other hand, the worm continues to browse the active session and self-propagates to personal contacts and groups, thus rapidly duplicating. Another specific tactic of the malware is that it does not have a fixed server. It has a pre-set Gmail account to check the subject or body of the most recent email in that inbox, to retrieve command-and-control addresses.

    Add WION as a Preferred Source

    “One notable feature of this malware is that it uses hardcoded credentials to log into its email account, from which it retrieves its C2 server. It is a very clever way to update its C2, maintain persistence, and evade detections or takedowns on a network level. If the malware cannot connect to the email account, it uses a hardcoded fallback C2 address,” read the report. Once installed, it can record keystrokes, take screenshots, and steal files.

    Trend of cyber attacks in Brazil

    The South American country has been targeted by several such attacks using the ubiquity of messaging vectors like WhatsApp. Earlier in September, another campaign dubbed Water Saci targeted Brazilians with a worm that propagates via WhatsApp Web known as SORVEPOTEL, which acts as a conduit for Maverick and Coyote, both .NET banking trojans. The campaign is reportedly ongoing and the worm continuously improves itself to target in ther region of Brazil and Argentina



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    How to apply for the Best Places to Work in Fintech 2026

    Fintech

    Why Payments Still Break Marketplaces (and How Fintech Can Finally Fix It): By Raman Korneu

    Fintech

    ‘Merchants, SMEs Can Use Multiple Point-of-sale Terminals’

    Fintech

    FINEXUS Champions Fintech Innovation by Hosting MAJECA MASSA with Support from Cyberview and Kolaxus

    Fintech

    Fintech startup Kaaj raises $3.8 Mn led by Kindred Ventures

    Fintech

    Teen Startup Founder Now CEO Of African Fintech Division

    Fintech
    Leave A Reply Cancel Reply

    Top Picks
    Cryptocurrency

    Cryptocurrency under attack by criminals, FBI says be aware

    Cryptocurrency

    Could This Surprising Cryptocurrency Become the Next XRP?

    Investments

    Vietnam Enterprise Investments Limited annonce la nomination d’Edphawin (Eddy) Jetjirawat en tant qu’administrateur indépendant non exécutif, à compter du 1er mars 2025 -Le 24 février 2025 à 08:00

    Editors Picks

    Cryptocurrency Billionaire Sells His South Florida Penthouse for $28.6 Million

    June 2, 2025

    Kamala Harris Can Advance ‘Sustainable Future For Cryptocurrencies,’ Says Industry Expert

    August 7, 2024

    Les cours du pétrole chutent sous le double effet des nouveaux droits de douane et… de l’OPEP

    April 3, 2025

    Cryptocurrency ‘sniper’ traders made $100 million in a day on Melania Trump’s memecoin

    May 6, 2025
    What's Hot

    Doris May Berry, founding member of Mayberry Investments, passes

    September 2, 2025

    David Fowler bolsters Norfolk board amid Chilean copper campaign

    October 2, 2025

    Entre le Mali et le minier Barrick Gold, un bras de fer pour l’or – Libération

    April 16, 2025
    Our Picks

    If You’d Invested $500 in Cryptocurrency XRP 5 Years Ago, Here’s How Much You’d Have Today

    August 21, 2025

    India’s Real Estate Sector Burdened By 4.4 Million Inheritance Disputes, Freezing $200 Billion In Assets

    October 30, 2024

    Solarworld Energy Solutions IPO day 3: GMP, subscription status to review. Good or bad for investors?

    September 25, 2025
    Weekly Top

    Foreign investors sell off US $7B in Mexican government bonds

    November 20, 2025

    UK fraud office probes $36m cryptocurrency collapse

    November 20, 2025

    Former chief agricultural negotiator talks trade under second Trump Administration | News

    November 20, 2025
    Editor's Pick

    Copper hits one-month peak on strong China factory data, weak dollar

    September 1, 2025

    MARTY FRIEDMAN, CHUCK BILLY, BOBBY BLITZ, JEFF LOOMIS, ANDREAS KISSER And Others To Join METAL ALLEGIANCE For Annual Anaheim Show

    October 15, 2024

    Plan for new labs at Oxford’s Wood Centre for Innovation

    July 24, 2024
    © 2025 Invest Intellect
    • Contact us
    • Privacy Policy
    • Terms and Conditions

    Type above and press Enter to search. Press Esc to cancel.