PANews reported on November 20th that, according to Cointelegraph , hackers in Brazil are spreading a worm - banking trojan combination via WhatsApp , delivering " Eternidade Stealer " to steal login information from cryptocurrency wallets and financial accounts. The worm hijacks accounts and intelligently filters groups and business contacts, spreading only to personal contacts; the trojan automatically downloads and runs, scanning local financial data and logging into multiple banks, exchanges, and wallets. This malware uses a pre-set Gmail account to obtain and update C2 commands, reverting to a hard-coded C2 connection when a connection fails to connect, thus maintaining persistence and evading logout. The security team SpiderLabs advises caution when clicking on unfamiliar or suspicious links, and to immediately freeze access to banks and cryptocurrency services if compromised.PANews reported on November 20th that, according to Cointelegraph , hackers in Brazil are spreading a worm - banking trojan combination via WhatsApp , delivering " Eternidade Stealer " to steal login information from cryptocurrency wallets and financial accounts. The worm hijacks accounts and intelligently filters groups and business contacts, spreading only to personal contacts; the trojan automatically downloads and runs, scanning local financial data and logging into multiple banks, exchanges, and wallets. This malware uses a pre-set Gmail account to obtain and update C2 commands, reverting to a hard-coded C2 connection when a connection fails to connect, thus maintaining persistence and evading logout. The security team SpiderLabs advises caution when clicking on unfamiliar or suspicious links, and to immediately freeze access to banks and cryptocurrency services if compromised.

A cryptographic worm attack spreading via WhatsApp has emerged in Brazil.

2025/11/20 12:06

PANews reported on November 20th that, according to Cointelegraph , hackers in Brazil are spreading a worm - banking trojan combination via WhatsApp , delivering " Eternidade Stealer " to steal login information from cryptocurrency wallets and financial accounts. The worm hijacks accounts and intelligently filters groups and business contacts, spreading only to personal contacts; the trojan automatically downloads and runs, scanning local financial data and logging into multiple banks, exchanges, and wallets. This malware uses a pre-set Gmail account to obtain and update C2 commands, reverting to a hard-coded C2 connection when a connection fails to connect, thus maintaining persistence and evading logout. The security team SpiderLabs advises caution when clicking on unfamiliar or suspicious links, and to immediately freeze access to banks and cryptocurrency services if compromised.

Market Opportunity
Octavia Logo
Octavia Price(VIA)
$0.0139
$0.0139$0.0139
0.00%
USD
Octavia (VIA) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.