Breaking 17:30 ICE agents to be deployed in U.S. airports amid TSA staffing shortages 17:00 Hundreds protest in Damascus against new alcohol restrictions 16:30 Zelenskiy calls on allies to maintain pressure on Russia ahead of US talks 16:15 Cuba says its military is preparing for a possible us invasion amid rising tensions 16:00 ICC prosecutor allegations remain under review despite media report of exoneration 15:30 Dalmatian pelican, one of the heaviest flying birds, sighted in eastern Türkiye 15:00 Iran threatens to fully close the Strait of Hormuz amid rising tensions with Washington 14:45 Seven killed in Qatar military helicopter crash including three Turkish nationals 14:43 Team of the Week: Morocco crowned African champion after 50 years… and the surprises continue 14:30 Suspicious death of police officer in Settat leads to detention of young woman 14:15 China signals more balanced trade and greater economic opening after record surplus 13:50 Trump orders deployment of immigration agents to US airports amid funding dispute 13:30 Slovenia limits fuel purchases as shortages hit petrol stations 13:00 Cuba begins recovery after second nationwide power grid collapse in a week 12:45 Paris mayoral candidate Sophia Chikirou briefly breaks electoral silence with social media post 12:30 Central African Republic closes two UN mission bases amid improved security 12:15 Millennium-old Shiva statue restored after being shattered into 10,000 fragments in Cambodia 12:00 France heads to polls in uncertain municipal elections 11:45 Taiwan confirms delayed US F-16s to begin arriving this year 11:30 Tencent integrates WeChat with OpenClaw AI agent amid China tech battle 11:15 Vietnam's Communist Party wins nearly 97% of assembly seats 11:00 Slovenia votes amid concerns over anti-Romany rhetoric 10:45 12 killed, dozens injured as bus collides with train in southeastern Bangladesh 10:30 UK minister says Trump speaks for himself on Iran deadline 10:15 Turkish journalist arrested over “misleading information” charges 10:00 Japan considers minesweeping in Hormuz if ceasefire is reached 09:45 Iran threatens to target strategic infrastructure after Trump ultimatum 09:30 Socialists battle to hold Paris as France votes in mayoral elections 09:15 Volkswagen CEO urges German carmakers to learn from China’s industrial strategy 09:00 Former FBI director Robert Mueller dies at 81 as Trump reacts 08:45 Helicopter crash in Qatar attributed to technical failure during routine flight 08:30 Cuba hit by second nationwide blackout in a week as energy crisis deepens 08:15 South Korea appoints Shin Hyun-Song as central bank governor to address economic challenges 08:00 Italians begin voting in crucial referendum on judicial reform

Brazil confronts rapid WhatsApp malware surge

Friday 21 November 2025 - 15:20
By: Dakir Madiha
Brazil confronts rapid WhatsApp malware surge

Brazil is facing a fast moving malware campaign that uses WhatsApp to infiltrate devices and spread through trusted contacts. Security analysts report a coordinated operation that blends social engineering, automated propagation, and a sophisticated trojan capable of stealing banking and cryptocurrency data. The audience includes cybersecurity professionals, policy analysts, and readers who follow digital threat trends in Latin America.

Researchers say the campaign exploits routine communication. Victims receive a WhatsApp message containing a ZIP file or a shortcut disguised as an everyday document such as a receipt, medical note, or administrative form. When opened, a hidden script activates and seizes control of the user’s WhatsApp Web session. The same malicious file is then sent automatically to everyone in the contact list. The process transforms each infected user into a new distribution point, creating a chain reaction that spreads through private and professional networks.

Investigators describe a two layer system. A Python module manages the automated spread through WhatsApp Web. A separate MSI installer deploys the second stage known as the Eternidade Stealer. This component gathers personal data and grants remote operators extensive control over the device. The attackers adjust commands, update templates, and download contact lists through a command and control server.

The campaign mirrors a broader trend observed across Brazil. Similar malware families including Maverick, Coyote, and Sorvepotel have recently targeted local users through WhatsApp Web manipulation and browser based techniques.

A trojan designed for financial theft

The second payload activates banking and cryptocurrency theft capabilities. It extracts passwords, cookies, authentication codes, and sensitive browsing data. It can perform web injections to interfere with online banking portals and searches for recovery phrases linked to cryptocurrency wallets or browser extensions. Attackers aim to empty bank accounts during login attempts and seize crypto assets when a signing request appears.

Investigators note that many victims only realize the attack after financial losses. The scheme leverages common digital habits as users switch between desktop browsers, mobile devices, and extensions without recognizing the increased exposure. Attackers reinforce the deception with convincing templates that resemble delivery updates or official notices.

Warning signs include unexpected file transfers from WhatsApp, slow browser performance, unfamiliar pop ups, alerts from antivirus tools about PowerShell or VBS scripts, and unknown browser extensions. Specialists urge users to disconnect WhatsApp Web at the first sign of suspicious behavior, change banking and crypto passwords from a secure device, revoke active wallet sessions, and restore systems from clean backups if required.

Researchers stress that the campaign progresses quickly. Early action can determine whether a user faces minor disruption or significant financial damage.


  • Fajr
  • Sunrise
  • Dhuhr
  • Asr
  • Maghrib
  • Isha

Read more

This website, walaw.press, uses cookies to provide you with a good browsing experience and to continuously improve our services. By continuing to browse this site, you agree to the use of these cookies.