The post Brazil Alerts Crypto Users to New WhatsApp Malware Campaign Deploying Hijacking Worm appeared on BitcoinEthereumNews.com. WhatsApp worm and trojan combo targets Brazilian crypto users with stealthy account hijacks. Malware uses a Gmail-based command system to evade shutdowns and update its operations. Redirector panel logs show global exposure, with most connection attempts from desktop systems. Brazilian authorities and cybersecurity analysts have raised an alarm over a fast-spreading malware campaign that is using WhatsApp messages to target crypto users through automated account hijacking and a sophisticated banking trojan. The operation, identified by researchers at Trustwave SpiderLabs, links a WhatsApp-propagated worm to a threat tool known as Eternidade Stealer, allowing attackers to obtain banking credentials, crypto exchange logins, and other sensitive financial information from infected devices. Researchers Trace Coordinated Activity Through WhatsApp-Based Lures According to SpiderLabs researchers Nathaniel Morales, John Basmayor, and Nikita Kazymirskyi, the campaign relies on social-engineering messages that imitate government notices, delivery updates, fraudulent investment groups, or even contacts from friends. Once a victim opens the malicious link, both the worm and the banking trojan install simultaneously. The worm immediately seizes the victim’s WhatsApp account, extracts the contact list, and filters out groups or business numbers to prioritize one-to-one targeting. During this process, the companion trojan delivers the Eternidade Stealer payload. The malware then scans the system for credentials linked to Brazilian banking platforms, fintech accounts, and crypto-related services, including wallets and exchanges. Researchers argue that this dual-stage structure has become increasingly common in Brazil’s cybercrime ecosystem, which has utilized WhatsApp for past campaigns, such as Water Saci, spanning 2024 and 2025. Malware Uses Gmail-Based Command Retrieval to Evade Takedowns Investigators report that the malware avoids traditional network shutdowns by using a preset Gmail account to receive updated commands. Instead of depending on a fixed command-and-control (C2) server, it logs into the hardcoded email address, checks for the latest instructions, and only falls back to… The post Brazil Alerts Crypto Users to New WhatsApp Malware Campaign Deploying Hijacking Worm appeared on BitcoinEthereumNews.com. WhatsApp worm and trojan combo targets Brazilian crypto users with stealthy account hijacks. Malware uses a Gmail-based command system to evade shutdowns and update its operations. Redirector panel logs show global exposure, with most connection attempts from desktop systems. Brazilian authorities and cybersecurity analysts have raised an alarm over a fast-spreading malware campaign that is using WhatsApp messages to target crypto users through automated account hijacking and a sophisticated banking trojan. The operation, identified by researchers at Trustwave SpiderLabs, links a WhatsApp-propagated worm to a threat tool known as Eternidade Stealer, allowing attackers to obtain banking credentials, crypto exchange logins, and other sensitive financial information from infected devices. Researchers Trace Coordinated Activity Through WhatsApp-Based Lures According to SpiderLabs researchers Nathaniel Morales, John Basmayor, and Nikita Kazymirskyi, the campaign relies on social-engineering messages that imitate government notices, delivery updates, fraudulent investment groups, or even contacts from friends. Once a victim opens the malicious link, both the worm and the banking trojan install simultaneously. The worm immediately seizes the victim’s WhatsApp account, extracts the contact list, and filters out groups or business numbers to prioritize one-to-one targeting. During this process, the companion trojan delivers the Eternidade Stealer payload. The malware then scans the system for credentials linked to Brazilian banking platforms, fintech accounts, and crypto-related services, including wallets and exchanges. Researchers argue that this dual-stage structure has become increasingly common in Brazil’s cybercrime ecosystem, which has utilized WhatsApp for past campaigns, such as Water Saci, spanning 2024 and 2025. Malware Uses Gmail-Based Command Retrieval to Evade Takedowns Investigators report that the malware avoids traditional network shutdowns by using a preset Gmail account to receive updated commands. Instead of depending on a fixed command-and-control (C2) server, it logs into the hardcoded email address, checks for the latest instructions, and only falls back to…

Brazil Alerts Crypto Users to New WhatsApp Malware Campaign Deploying Hijacking Worm

  • WhatsApp worm and trojan combo targets Brazilian crypto users with stealthy account hijacks.
  • Malware uses a Gmail-based command system to evade shutdowns and update its operations.
  • Redirector panel logs show global exposure, with most connection attempts from desktop systems.

Brazilian authorities and cybersecurity analysts have raised an alarm over a fast-spreading malware campaign that is using WhatsApp messages to target crypto users through automated account hijacking and a sophisticated banking trojan.

The operation, identified by researchers at Trustwave SpiderLabs, links a WhatsApp-propagated worm to a threat tool known as Eternidade Stealer, allowing attackers to obtain banking credentials, crypto exchange logins, and other sensitive financial information from infected devices.

Researchers Trace Coordinated Activity Through WhatsApp-Based Lures

According to SpiderLabs researchers Nathaniel Morales, John Basmayor, and Nikita Kazymirskyi, the campaign relies on social-engineering messages that imitate government notices, delivery updates, fraudulent investment groups, or even contacts from friends.

Once a victim opens the malicious link, both the worm and the banking trojan install simultaneously. The worm immediately seizes the victim’s WhatsApp account, extracts the contact list, and filters out groups or business numbers to prioritize one-to-one targeting.

During this process, the companion trojan delivers the Eternidade Stealer payload. The malware then scans the system for credentials linked to Brazilian banking platforms, fintech accounts, and crypto-related services, including wallets and exchanges. Researchers argue that this dual-stage structure has become increasingly common in Brazil’s cybercrime ecosystem, which has utilized WhatsApp for past campaigns, such as Water Saci, spanning 2024 and 2025.

Malware Uses Gmail-Based Command Retrieval to Evade Takedowns

Investigators report that the malware avoids traditional network shutdowns by using a preset Gmail account to receive updated commands. Instead of depending on a fixed command-and-control (C2) server, it logs into the hardcoded email address, checks for the latest instructions, and only falls back to a static C2 domain if the email is unreachable. SpiderLabs referred to this method as a way to maintain persistence while reducing the likelihood of detection.

Related: New Malware Threat: Cthulhu Stealer Targets Mac and Crypto

During infrastructure mapping, analysts linked the initial domain, *serverseistemasatu[.]com,* to a server hosting multiple threat-actor panels, including a Redirector System used to track incoming connections. Of the 453 visits logged, 451 were blocked due to geographic restrictions, allowing only Brazil and Argentina.

However, log data showed 454 communication attempts across 38 countries, including the United States (196), the Netherlands (37), Germany (32), the United Kingdom (23), and France (19). Only three interactions originated from Brazil.

The panel also recorded OS statistics indicating 40% of connections came from unidentified systems, followed by Windows (25%), macOS (21%), Linux (10%), and Android (4%). Investigators stated that the data shows most interactions occurred from desktop environments.

Related: How Browser Wallet Permissions Were Exploited in the Latest LinkedIn Job Offer Scam

Disclaimer: The information presented in this article is for informational and educational purposes only. The article does not constitute financial advice or advice of any kind. Coin Edition is not responsible for any losses incurred as a result of the utilization of content, products, or services mentioned. Readers are advised to exercise caution before taking any action related to the company.

Source: https://coinedition.com/brazil-alerts-crypto-users-to-new-whatsapp-malware-campaign-deploying-hijacking-worm/

Market Opportunity
John Tsubasa Rivals Logo
John Tsubasa Rivals Price(JOHN)
$0.00792
$0.00792$0.00792
-0.25%
USD
John Tsubasa Rivals (JOHN) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Cardano Price Prediction: ADA To Rally 6000%? Win For Grayscale Large Cap Fund

Cardano Price Prediction: ADA To Rally 6000%? Win For Grayscale Large Cap Fund

The post Cardano Price Prediction: ADA To Rally 6000%? Win For Grayscale Large Cap Fund appeared on BitcoinEthereumNews.com. Cardano (ADA) price is back in the spotlight as analysts point to massive upside potential following a major win for Grayscale’s Digital Large Cap Fund. Crypto expert Deezy has highlighted ADA’s history of explosive rallies, noting gains of up to 6,000% in past cycles. Grayscale’s fund holds Cardano alongside Bitcoin, Ethereum, XRP, and Solana. With SEC approval, investors see a powerful mix of technical strength and fresh institutional demand setting the stage for another breakout. Cardano Price Prediction: ADA Price To Skyrocket by 6000% , Says Expert Cardano has shown a clear history of explosive growth during previous cycles. In its first major move, ADA gained over 6,000% within just a few months. Later, the second cycle produced a strong 3,000% rally that lasted almost a year. Now, if this pattern continues according to an analysis by crypto expert Deezy, even with a 50% decline in strength compared to the last move, ADA could still deliver a 1,500% pump. That projection points directly toward the $10 range. https://twitter.com/deezy_BTC/status/1968344589846315017/photo/1 The chart also shows strong support forming after long consolidation periods. Each time ADA reached oversold conditions, powerful rallies followed. Currently, the indicators are curling upward again, hinting at momentum returning to the upside. With historical cycles, technical indicators, and consistent recovery patterns lining up, Cardano looks ready for another significant run. If history rhymes, the $10 target is within reach. Grayscale Large Cap Fund Will Hold Cardano, Four More Top Cryptos At the same time, the broader altcoin market just received a major boost with Cardano included. On September 17, the SEC approved the listing and trading of the Grayscale Digital Large Cap Fund (GDLC) on NYSE Arca. This includes Bitcoin, Ethereum, XRP, Solana, and Cardano. As a result, traditional investors will gain regulated access to ADA alongside these other top…
Share
BitcoinEthereumNews2025/09/18 23:26
The 5 Best AI Sales Assistants for SDR Teams in 2026

The 5 Best AI Sales Assistants for SDR Teams in 2026

Sales teams are under pressure to generate more pipeline while response rates decline and headcount stays flat. Reps are expected to personalize outreach and spend
Share
AI Journal2026/01/18 06:14
Chris Burniske Forecasts Big Changes Coming to Cryptocurrency Market

Chris Burniske Forecasts Big Changes Coming to Cryptocurrency Market

TLDR Chris Burniske predicts that price flows will start driving crypto market narratives. Burniske foresees underperforming cryptocurrencies gaining more attention. Coinbase predicts growth in Q4 2025 driven by positive macroeconomic factors. Tom Lee suggests Bitcoin and Ethereum could benefit from potential Fed rate cuts. A major shift is looming in the cryptocurrency market, according to [...] The post Chris Burniske Forecasts Big Changes Coming to Cryptocurrency Market appeared first on CoinCentral.
Share
Coincentral2025/09/18 00:17