Breaking 18:30 Jordan Bardella distances himself from Donald Trump, criticizes Iran's regime 18:00 Seven French customs officers referred to court over drug trafficking allegations 17:53 How US inflation evolved across history and presidencies 17:50 Top countries dominate global fig production in 2025 17:30 U.S. envoy Steve Witkoff scheduled to meet Netanyahu following Rafah border reopening 17:20 Greenland PM warns US still seeks control despite Trump's retreat 17:00 OCP partners with Mistral AI to accelerate its AI-driven transformation 16:50 Global markets plunge after Trump's Fed chair pick 16:30 Severe weather: Spanish civil guard warns of collapse of the Ceuta border barrier 16:26 Arab countries by predominant Islamic schools of jurisprudence 16:20 EU foreign policy chief warns European army would be dangerous 16:00 Morocco: Government council to review judicial experts and dam safety issues 15:50 Fashion spotlight on Milano Cortina 2026 opening ceremony 15:30 Tanger Med surpasses 11 million containers handled in 2025 15:03 Morocco reverts to Greenwich Mean Time on February 15 15:00 US And South Korea report progress on tariff discussions 14:50 MIT AI model suggests recipes for novel materials 14:44 Richard Duke Buchan III: A seasoned diplomat leading U.S. representation in Morocco 14:30 Ligue 1: Moroccan International Souffian El Karouani close to joining Marseille 14:20 Morocco unites in solidarity after devastating floods 14:17 Young leaders reshaping global politics 14:00 Bangladesh: Former Prime Minister Sheikh Hasina sentenced to additional prison term 13:50 Copper prices plunge amid broad metals sell-off shaking global markets 13:40 Switzerland tops global financial secrecy index, sparking transparency debates 13:30 Industry: Ocp maintenance solutions opens a subsidiary in Saudi Arabia 13:20 Aviation leaders warn of supply chain strains and geopolitical risks 13:00 Morocco: Astronomical calculations indicate likely start date of Ramadan 12:50 Mexico defies Trump pressure with humanitarian aid to Cuba 12:30 Partially burned body found near hardware store in Marseille 12:00 Ukraine Conflict: trilateral talks scheduled in Abu Dhabi 11:50 Japan extracts rare earths at record ocean depth 11:30 Four foreign nationals arrested in Tehran over riot involvement 11:20 China's solar capacity to surpass coal for first time in 2026 11:19 China leads world's largest foreign currency reserve holders 11:00 Severe weather in Northern Morocco: school closures announced across several provinces 10:50 Musk hails AI-only social network as dawn of singularity 10:30 Women’s Empowerment: Morocco’s experience highlighted in Egypt 10:20 Trump optimistic on Iran deal as Tehran reviews talks 10:00 Grammy Awards 2026: Bad Bunny, Kendrick Lamar and Billie Eilish take top honors 09:50 Taiwan deploys missiles after Chinese helicopter enters its air defense zone 09:30 Epstein files reveal shipment of sacred Kaaba cloth to the United States 09:20 France and Morocco negotiate landmark bilateral treaty 09:00 Infant formula: popote recalls two batches in France over toxin threshold change 08:50 Moroccans lead beneficiaries of Spain's mass migrant regularization 08:30 China executes four leaders of Myanmar-based criminal gangs 08:20 Gold and silver extend historic plunge amid Asian market rout 08:00 Woman fatally stabbed in busy area of London 07:50 Saudi crown prince checks on HM King Mohammed VI's health 07:30 Qatari emir and French president discuss Iran and regional security 07:00 Norway: Epstein case further weakens crown princess Mette-Marit

Brazil confronts rapid WhatsApp malware surge

Friday 21 November 2025 - 15:20
By: Dakir Madiha
Brazil confronts rapid WhatsApp malware surge

Brazil is facing a fast moving malware campaign that uses WhatsApp to infiltrate devices and spread through trusted contacts. Security analysts report a coordinated operation that blends social engineering, automated propagation, and a sophisticated trojan capable of stealing banking and cryptocurrency data. The audience includes cybersecurity professionals, policy analysts, and readers who follow digital threat trends in Latin America.

Researchers say the campaign exploits routine communication. Victims receive a WhatsApp message containing a ZIP file or a shortcut disguised as an everyday document such as a receipt, medical note, or administrative form. When opened, a hidden script activates and seizes control of the user’s WhatsApp Web session. The same malicious file is then sent automatically to everyone in the contact list. The process transforms each infected user into a new distribution point, creating a chain reaction that spreads through private and professional networks.

Investigators describe a two layer system. A Python module manages the automated spread through WhatsApp Web. A separate MSI installer deploys the second stage known as the Eternidade Stealer. This component gathers personal data and grants remote operators extensive control over the device. The attackers adjust commands, update templates, and download contact lists through a command and control server.

The campaign mirrors a broader trend observed across Brazil. Similar malware families including Maverick, Coyote, and Sorvepotel have recently targeted local users through WhatsApp Web manipulation and browser based techniques.

A trojan designed for financial theft

The second payload activates banking and cryptocurrency theft capabilities. It extracts passwords, cookies, authentication codes, and sensitive browsing data. It can perform web injections to interfere with online banking portals and searches for recovery phrases linked to cryptocurrency wallets or browser extensions. Attackers aim to empty bank accounts during login attempts and seize crypto assets when a signing request appears.

Investigators note that many victims only realize the attack after financial losses. The scheme leverages common digital habits as users switch between desktop browsers, mobile devices, and extensions without recognizing the increased exposure. Attackers reinforce the deception with convincing templates that resemble delivery updates or official notices.

Warning signs include unexpected file transfers from WhatsApp, slow browser performance, unfamiliar pop ups, alerts from antivirus tools about PowerShell or VBS scripts, and unknown browser extensions. Specialists urge users to disconnect WhatsApp Web at the first sign of suspicious behavior, change banking and crypto passwords from a secure device, revoke active wallet sessions, and restore systems from clean backups if required.

Researchers stress that the campaign progresses quickly. Early action can determine whether a user faces minor disruption or significant financial damage.


  • Fajr
  • Sunrise
  • Dhuhr
  • Asr
  • Maghrib
  • Isha

Read more

This website, walaw.press, uses cookies to provide you with a good browsing experience and to continuously improve our services. By continuing to browse this site, you agree to the use of these cookies.