The post Brazil Alerts Crypto Users to New WhatsApp Malware Campaign Deploying Hijacking Worm appeared on BitcoinEthereumNews.com. WhatsApp worm and trojan combo targets Brazilian crypto users with stealthy account hijacks. Malware uses a Gmail-based command system to evade shutdowns and update its operations. Redirector panel logs show global exposure, with most connection attempts from desktop systems. Brazilian authorities and cybersecurity analysts have raised an alarm over a fast-spreading malware campaign that is using WhatsApp messages to target crypto users through automated account hijacking and a sophisticated banking trojan. The operation, identified by researchers at Trustwave SpiderLabs, links a WhatsApp-propagated worm to a threat tool known as Eternidade Stealer, allowing attackers to obtain banking credentials, crypto exchange logins, and other sensitive financial information from infected devices. Researchers Trace Coordinated Activity Through WhatsApp-Based Lures According to SpiderLabs researchers Nathaniel Morales, John Basmayor, and Nikita Kazymirskyi, the campaign relies on social-engineering messages that imitate government notices, delivery updates, fraudulent investment groups, or even contacts from friends. Once a victim opens the malicious link, both the worm and the banking trojan install simultaneously. The worm immediately seizes the victim’s WhatsApp account, extracts the contact list, and filters out groups or business numbers to prioritize one-to-one targeting. During this process, the companion trojan delivers the Eternidade Stealer payload. The malware then scans the system for credentials linked to Brazilian banking platforms, fintech accounts, and crypto-related services, including wallets and exchanges. Researchers argue that this dual-stage structure has become increasingly common in Brazil’s cybercrime ecosystem, which has utilized WhatsApp for past campaigns, such as Water Saci, spanning 2024 and 2025. Malware Uses Gmail-Based Command Retrieval to Evade Takedowns Investigators report that the malware avoids traditional network shutdowns by using a preset Gmail account to receive updated commands. Instead of depending on a fixed command-and-control (C2) server, it logs into the hardcoded email address, checks for the latest instructions, and only falls back to… The post Brazil Alerts Crypto Users to New WhatsApp Malware Campaign Deploying Hijacking Worm appeared on BitcoinEthereumNews.com. WhatsApp worm and trojan combo targets Brazilian crypto users with stealthy account hijacks. Malware uses a Gmail-based command system to evade shutdowns and update its operations. Redirector panel logs show global exposure, with most connection attempts from desktop systems. Brazilian authorities and cybersecurity analysts have raised an alarm over a fast-spreading malware campaign that is using WhatsApp messages to target crypto users through automated account hijacking and a sophisticated banking trojan. The operation, identified by researchers at Trustwave SpiderLabs, links a WhatsApp-propagated worm to a threat tool known as Eternidade Stealer, allowing attackers to obtain banking credentials, crypto exchange logins, and other sensitive financial information from infected devices. Researchers Trace Coordinated Activity Through WhatsApp-Based Lures According to SpiderLabs researchers Nathaniel Morales, John Basmayor, and Nikita Kazymirskyi, the campaign relies on social-engineering messages that imitate government notices, delivery updates, fraudulent investment groups, or even contacts from friends. Once a victim opens the malicious link, both the worm and the banking trojan install simultaneously. The worm immediately seizes the victim’s WhatsApp account, extracts the contact list, and filters out groups or business numbers to prioritize one-to-one targeting. During this process, the companion trojan delivers the Eternidade Stealer payload. The malware then scans the system for credentials linked to Brazilian banking platforms, fintech accounts, and crypto-related services, including wallets and exchanges. Researchers argue that this dual-stage structure has become increasingly common in Brazil’s cybercrime ecosystem, which has utilized WhatsApp for past campaigns, such as Water Saci, spanning 2024 and 2025. Malware Uses Gmail-Based Command Retrieval to Evade Takedowns Investigators report that the malware avoids traditional network shutdowns by using a preset Gmail account to receive updated commands. Instead of depending on a fixed command-and-control (C2) server, it logs into the hardcoded email address, checks for the latest instructions, and only falls back to…

Brazil Alerts Crypto Users to New WhatsApp Malware Campaign Deploying Hijacking Worm

For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com
  • WhatsApp worm and trojan combo targets Brazilian crypto users with stealthy account hijacks.
  • Malware uses a Gmail-based command system to evade shutdowns and update its operations.
  • Redirector panel logs show global exposure, with most connection attempts from desktop systems.

Brazilian authorities and cybersecurity analysts have raised an alarm over a fast-spreading malware campaign that is using WhatsApp messages to target crypto users through automated account hijacking and a sophisticated banking trojan.

The operation, identified by researchers at Trustwave SpiderLabs, links a WhatsApp-propagated worm to a threat tool known as Eternidade Stealer, allowing attackers to obtain banking credentials, crypto exchange logins, and other sensitive financial information from infected devices.

Researchers Trace Coordinated Activity Through WhatsApp-Based Lures

According to SpiderLabs researchers Nathaniel Morales, John Basmayor, and Nikita Kazymirskyi, the campaign relies on social-engineering messages that imitate government notices, delivery updates, fraudulent investment groups, or even contacts from friends.

Once a victim opens the malicious link, both the worm and the banking trojan install simultaneously. The worm immediately seizes the victim’s WhatsApp account, extracts the contact list, and filters out groups or business numbers to prioritize one-to-one targeting.

During this process, the companion trojan delivers the Eternidade Stealer payload. The malware then scans the system for credentials linked to Brazilian banking platforms, fintech accounts, and crypto-related services, including wallets and exchanges. Researchers argue that this dual-stage structure has become increasingly common in Brazil’s cybercrime ecosystem, which has utilized WhatsApp for past campaigns, such as Water Saci, spanning 2024 and 2025.

Malware Uses Gmail-Based Command Retrieval to Evade Takedowns

Investigators report that the malware avoids traditional network shutdowns by using a preset Gmail account to receive updated commands. Instead of depending on a fixed command-and-control (C2) server, it logs into the hardcoded email address, checks for the latest instructions, and only falls back to a static C2 domain if the email is unreachable. SpiderLabs referred to this method as a way to maintain persistence while reducing the likelihood of detection.

Related: New Malware Threat: Cthulhu Stealer Targets Mac and Crypto

During infrastructure mapping, analysts linked the initial domain, *serverseistemasatu[.]com,* to a server hosting multiple threat-actor panels, including a Redirector System used to track incoming connections. Of the 453 visits logged, 451 were blocked due to geographic restrictions, allowing only Brazil and Argentina.

However, log data showed 454 communication attempts across 38 countries, including the United States (196), the Netherlands (37), Germany (32), the United Kingdom (23), and France (19). Only three interactions originated from Brazil.

The panel also recorded OS statistics indicating 40% of connections came from unidentified systems, followed by Windows (25%), macOS (21%), Linux (10%), and Android (4%). Investigators stated that the data shows most interactions occurred from desktop environments.

Related: How Browser Wallet Permissions Were Exploited in the Latest LinkedIn Job Offer Scam

Disclaimer: The information presented in this article is for informational and educational purposes only. The article does not constitute financial advice or advice of any kind. Coin Edition is not responsible for any losses incurred as a result of the utilization of content, products, or services mentioned. Readers are advised to exercise caution before taking any action related to the company.

Source: https://coinedition.com/brazil-alerts-crypto-users-to-new-whatsapp-malware-campaign-deploying-hijacking-worm/

Market Opportunity
John Tsubasa Rivals Logo
John Tsubasa Rivals Price(JOHN)
$0.00124
$0.00124$0.00124
0.00%
USD
John Tsubasa Rivals (JOHN) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

IP Hits $11.75, HYPE Climbs to $55, BlockDAG Surpasses Both with $407M Presale Surge!

IP Hits $11.75, HYPE Climbs to $55, BlockDAG Surpasses Both with $407M Presale Surge!

The post IP Hits $11.75, HYPE Climbs to $55, BlockDAG Surpasses Both with $407M Presale Surge! appeared on BitcoinEthereumNews.com. Crypto News 17 September 2025 | 18:00 Discover why BlockDAG’s upcoming Awakening Testnet launch makes it the best crypto to buy today as Story (IP) price jumps to $11.75 and Hyperliquid hits new highs. Recent crypto market numbers show strength but also some limits. The Story (IP) price jump has been sharp, fueled by big buybacks and speculation, yet critics point out that revenue still lags far behind its valuation. The Hyperliquid (HYPE) price looks solid around the mid-$50s after a new all-time high, but questions remain about sustainability once the hype around USDH proposals cools down. So the obvious question is: why chase coins that are either stretched thin or at risk of retracing when you could back a network that’s already proving itself on the ground? That’s where BlockDAG comes in. While other chains are stuck dealing with validator congestion or outages, BlockDAG’s upcoming Awakening Testnet will be stress-testing its EVM-compatible smart chain with real miners before listing. For anyone looking for the best crypto coin to buy, the choice between waiting on fixes or joining live progress feels like an easy one. BlockDAG: Smart Chain Running Before Launch Ethereum continues to wrestle with gas congestion, and Solana is still known for network freezes, yet BlockDAG is already showing a different picture. Its upcoming Awakening Testnet, set to launch on September 25, isn’t just a demo; it’s a live rollout where the chain’s base protocols are being stress-tested with miners connected globally. EVM compatibility is active, account abstraction is built in, and tools like updated vesting contracts and Stratum integration are already functional. Instead of waiting for fixes like other networks, BlockDAG is proving its infrastructure in real time. What makes this even more important is that the technology is operational before the coin even hits exchanges. That…
Share
BitcoinEthereumNews2025/09/18 00:32
China Blocks Nvidia’s RTX Pro 6000D as Local Chips Rise

China Blocks Nvidia’s RTX Pro 6000D as Local Chips Rise

The post China Blocks Nvidia’s RTX Pro 6000D as Local Chips Rise appeared on BitcoinEthereumNews.com. China Blocks Nvidia’s RTX Pro 6000D as Local Chips Rise China’s internet regulator has ordered the country’s biggest technology firms, including Alibaba and ByteDance, to stop purchasing Nvidia’s RTX Pro 6000D GPUs. According to the Financial Times, the move shuts down the last major channel for mass supplies of American chips to the Chinese market. Why Beijing Halted Nvidia Purchases Chinese companies had planned to buy tens of thousands of RTX Pro 6000D accelerators and had already begun testing them in servers. But regulators intervened, halting the purchases and signaling stricter controls than earlier measures placed on Nvidia’s H20 chip. Image: Nvidia An audit compared Huawei and Cambricon processors, along with chips developed by Alibaba and Baidu, against Nvidia’s export-approved products. Regulators concluded that Chinese chips had reached performance levels comparable to the restricted U.S. models. This assessment pushed authorities to advise firms to rely more heavily on domestic processors, further tightening Nvidia’s already limited position in China. China’s Drive Toward Tech Independence The decision highlights Beijing’s focus on import substitution — developing self-sufficient chip production to reduce reliance on U.S. supplies. “The signal is now clear: all attention is focused on building a domestic ecosystem,” said a representative of a leading Chinese tech company. Nvidia had unveiled the RTX Pro 6000D in July 2025 during CEO Jensen Huang’s visit to Beijing, in an attempt to keep a foothold in China after Washington restricted exports of its most advanced chips. But momentum is shifting. Industry sources told the Financial Times that Chinese manufacturers plan to triple AI chip production next year to meet growing demand. They believe “domestic supply will now be sufficient without Nvidia.” What It Means for the Future With Huawei, Cambricon, Alibaba, and Baidu stepping up, China is positioning itself for long-term technological independence. Nvidia, meanwhile, faces…
Share
BitcoinEthereumNews2025/09/18 01:37
Uphold’s Massive 1.59 Billion XRP Holdings Shocks Community, CEO Reveals The Real Owners

Uphold’s Massive 1.59 Billion XRP Holdings Shocks Community, CEO Reveals The Real Owners

Uphold, a cloud-based digital financial service platform, has come under the spotlight after on-chain data confirmed that it safeguards approximately 1.59 billion XRP. According to Uphold’s Chief Executive Officer (CEO), Simon McLoughlin, these tokens are fully owned by customers, not the exchange itself.  Uphold Clarifies Massive XRP Holdings The crypto community was taken by surprise […]
Share
Bitcoinist2025/09/18 00:30