A newly identified WhatsApp-based worm-and-trojan campaign in Brazil is compromising crypto wallets and bank accounts through a rapidly spreading malware cluster dubbed Eternidade.A newly identified WhatsApp-based worm-and-trojan campaign in Brazil is compromising crypto wallets and bank accounts through a rapidly spreading malware cluster dubbed Eternidade.

Brazil Faces Surge in WhatsApp Worm Attacks Targeting Crypto and Banking Apps

2025/11/21 22:23
3분 읽기
이 콘텐츠에 대한 의견이나 우려 사항이 있으시면 crypto.news@mexc.com으로 연락주시기 바랍니다

A newly identified WhatsApp-based worm-and-trojan campaign in Brazil is compromising crypto wallets and bank accounts through a rapidly spreading malware cluster dubbed Eternidade.

Researchers Identify New Multi-Stage Threat

Brazilian crypto users are being warned about an emerging malware operation that leverages WhatsApp hijacking to spread a banking trojan designed to harvest financial credentials. Trustwave SpiderLabs researchers have disclosed that the campaign revolves around a newly identified stealer known as Eternidade, a Delphi-based malware capable of dynamically updating its command-and-control infrastructure and stealthily collecting data from victims.

Researchers Nathaniel Morales, John Basmayor, and Nikita Kazymirskyi noted that WhatsApp remains central to Brazil’s cybercriminal ecosystem, stating, 

How the Infection Chain Works

According to the research team, the ongoing operation begins with social engineering messages delivered via WhatsApp. These lures mimic familiar formats, such as delivery notifications, fraudulent investment groups, and “fake government programs”, to trick recipients into clicking malicious links.

Once clicked, the link triggers the deployment of both a hijacking worm and the Eternidade banking trojan. The worm immediately takes control of the victim’s WhatsApp account, extracts the contact list, and selectively targets individual contacts using “smart filtering,” bypassing business groups to maximize the likelihood of personal engagement.

Simultaneously, a trojan file is silently downloaded on the device. This component installs the Eternidade Stealer in the background, enabling attackers to scan for credentials tied to major Brazilian banks, fintech platforms, and cryptocurrency exchanges and wallets.

Adaptive Command-and-Control via Gmail

One of the campaign’s most crucial traits is its unconventional method for receiving updated commands. Instead of relying on static server addresses, Eternidade uses hardcoded credentials to log into a Gmail account via IMAP. This allows the attackers to send updated instructions simply by emailing the controlled account.

The researchers highlighted this technique in their report: 

Related Malware Activity

The Eternidade operation follows closely behind another Brazil-focused malware wave known as Water Saci, which used a WhatsApp Web worm called SORVEPOTEL to distribute Maverick, a .NET-based banking trojan linked to earlier Coyote malware variants. These incidents underscore a persistent trend in the region: the use of WhatsApp as a primary vector and the enduring reliance on Delphi-based tools for malware development.

Safety Recommendations

Security experts are advising WhatsApp users to avoid clicking unfamiliar links, even when sent by trusted contacts. Confirming suspicious messages through alternate communication channels is recommended, particularly when little context accompanies the link.

Disclaimer: This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice

시장 기회
SURGE 로고
SURGE 가격(SURGE)
$0.01337
$0.01337$0.01337
-11.51%
USD
SURGE (SURGE) 실시간 가격 차트
면책 조항: 본 사이트에 재게시된 글들은 공개 플랫폼에서 가져온 것으로 정보 제공 목적으로만 제공됩니다. 이는 반드시 MEXC의 견해를 반영하는 것은 아닙니다. 모든 권리는 원저자에게 있습니다. 제3자의 권리를 침해하는 콘텐츠가 있다고 판단될 경우, crypto.news@mexc.com으로 연락하여 삭제 요청을 해주시기 바랍니다. MEXC는 콘텐츠의 정확성, 완전성 또는 시의적절성에 대해 어떠한 보증도 하지 않으며, 제공된 정보에 기반하여 취해진 어떠한 조치에 대해서도 책임을 지지 않습니다. 본 콘텐츠는 금융, 법률 또는 기타 전문적인 조언을 구성하지 않으며, MEXC의 추천이나 보증으로 간주되어서는 안 됩니다.

$30,000 in PRL + 15,000 USDT

$30,000 in PRL + 15,000 USDT$30,000 in PRL + 15,000 USDT

Deposit & trade PRL to boost your rewards!