Breaking 17:00 Sudan: first commercial flight lands in Khartoum after nearly three years 16:40 Venezuela: human rights activist Javier Tarazona freed after over four years in prison 16:20 Saint-Gobain Sekurit centralizes European automotive glass rework in Kenitra, Morocco 16:00 DRC: landslide at Rubaya mine could leave at least 200 dead, authorities fear 15:40 Ukraine: Russian strike hits maternity hospital in Zaporizhzhia, six injured 15:20 Jewish school in Paris vandalized overnight, religious plaque destroyed 15:00 Tetouan schools closed on Monday due to severe weather 14:40 Waymo aims to raise 16 billion dollars to expand autonomous vehicle services 14:20 New car sales in France down 6.55% in January 14:20 Team of the week: from Nador to Ksar El Kebir, the test of action 14:00 Preventive evacuations ordered in Sidi Kacem amid rising sebour river levels 13:40 Crans-montana fire death toll rises to 41 after victim dies from injuries 13:20 Joseph Aoun visits Spain on official trip 13:00 Fuel prices rise again in Morocco as diesel and gasoline costs increase 12:40 Moroccan lawyers intensify strike, paralyzing courts 12:20 Floods hit Ksar El Kebir: army and rescue teams evacuate residents 12:00 Türkiye expresses condolences over deadly landslide in DR Congo 11:40 Rafah crossing in Gaza reopens with severe restrictions 11:20 Turkey bus accident kills eight, injures 26 11:00 Türkiye condemns deadly terrorist attacks in Pakistan’s Balochistan province 10:40 Saudi Arabia-Pakistan defense pact will not include Turkey 10:20 New winter storm hits the United States 10:00 Iran labels European armies “terrorist” in retaliation for EU measures 09:40 Controversial speed camera near Italian border: Ventimiglia found guilty of abusive procedure 09:20 Capgemini to sell subsidiary working with US immigration agency ICE 09:00 Ukraine: two killed in Russian drone strike on Dnipro 08:40 Trump says Iran is “talking to us” amid rising tensions 08:20 Switzerland: dozens killed in bar fire at Crans-Montana ski resort 07:56 Majority bloc backs Nouri al-Maliki for prime minister despite Trump warnings

Brazil confronts rapid WhatsApp malware surge

Friday 21 November 2025 - 15:20
By: Dakir Madiha
Brazil confronts rapid WhatsApp malware surge

Brazil is facing a fast moving malware campaign that uses WhatsApp to infiltrate devices and spread through trusted contacts. Security analysts report a coordinated operation that blends social engineering, automated propagation, and a sophisticated trojan capable of stealing banking and cryptocurrency data. The audience includes cybersecurity professionals, policy analysts, and readers who follow digital threat trends in Latin America.

Researchers say the campaign exploits routine communication. Victims receive a WhatsApp message containing a ZIP file or a shortcut disguised as an everyday document such as a receipt, medical note, or administrative form. When opened, a hidden script activates and seizes control of the user’s WhatsApp Web session. The same malicious file is then sent automatically to everyone in the contact list. The process transforms each infected user into a new distribution point, creating a chain reaction that spreads through private and professional networks.

Investigators describe a two layer system. A Python module manages the automated spread through WhatsApp Web. A separate MSI installer deploys the second stage known as the Eternidade Stealer. This component gathers personal data and grants remote operators extensive control over the device. The attackers adjust commands, update templates, and download contact lists through a command and control server.

The campaign mirrors a broader trend observed across Brazil. Similar malware families including Maverick, Coyote, and Sorvepotel have recently targeted local users through WhatsApp Web manipulation and browser based techniques.

A trojan designed for financial theft

The second payload activates banking and cryptocurrency theft capabilities. It extracts passwords, cookies, authentication codes, and sensitive browsing data. It can perform web injections to interfere with online banking portals and searches for recovery phrases linked to cryptocurrency wallets or browser extensions. Attackers aim to empty bank accounts during login attempts and seize crypto assets when a signing request appears.

Investigators note that many victims only realize the attack after financial losses. The scheme leverages common digital habits as users switch between desktop browsers, mobile devices, and extensions without recognizing the increased exposure. Attackers reinforce the deception with convincing templates that resemble delivery updates or official notices.

Warning signs include unexpected file transfers from WhatsApp, slow browser performance, unfamiliar pop ups, alerts from antivirus tools about PowerShell or VBS scripts, and unknown browser extensions. Specialists urge users to disconnect WhatsApp Web at the first sign of suspicious behavior, change banking and crypto passwords from a secure device, revoke active wallet sessions, and restore systems from clean backups if required.

Researchers stress that the campaign progresses quickly. Early action can determine whether a user faces minor disruption or significant financial damage.


  • Fajr
  • Sunrise
  • Dhuhr
  • Asr
  • Maghrib
  • Isha

Read more

This website, walaw.press, uses cookies to provide you with a good browsing experience and to continuously improve our services. By continuing to browse this site, you agree to the use of these cookies.