Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnSquareMore
WhatsApp Weaponized in Brazil as New Malware Campaign Targets Crypto Users

WhatsApp Weaponized in Brazil as New Malware Campaign Targets Crypto Users

DeFi PlanetDeFi Planet2025/11/20 20:30
By:DeFi Planet

Quick Breakdown 

  • Cybercriminals in Brazil are using WhatsApp to spread a worm and banking trojan that steals crypto and financial data.
  • The malware hijacks WhatsApp sessions, scans devices for banking and wallet apps, and propagates through victim contact lists.
  • Rising crypto adoption in Brazil is attracting sophisticated threats, including AI-powered malware and cross-platform stealers.

 

Cybercriminals in Brazil have launched a sophisticated malware operation that uses WhatsApp as the primary delivery channel to hijack devices and steal financial data, including access to crypto wallets. 

🚨 A new WhatsApp worm is spreading fast in Brazil.

It hijacks chats, sends fake messages to all your contacts, and installs a program that steals bank and crypto logins.

… and it updates itself through an email inbox to stay hidden.

Read here ↓

— The Hacker News (@TheHackersNews) November 19, 2025

The discovery was made by Trustwave’s SpiderLabs, which identified the campaign deploying the “Eternidade Stealer,” a tool designed to quietly extract sensitive information from banking apps, fintech platforms, and crypto exchanges.

Social engineering fuels the infection chain

According to researchers, the attackers rely heavily on WhatsApp-based social engineering, sending victims messages disguised as government benefits, delivery updates, or investment opportunities. Once a user taps the malicious link, an automated sequence takes over, hijacking the victim’s WhatsApp session and downloading an MSI installer in the background.

This installer deploys a Delphi-based banking trojan that scans the device for financial applications such as Bradesco, BTG Pactual, Binance, Coinbase, MetaMask, and Trust Wallet. The moment it detects one of these applications, the malware decrypts and launches its next-stage payload.

Self-spreading worm and stealthy C2 communication

One of the campaign’s more alarming traits is its ability to spread itself. The worm accesses the victim’s WhatsApp contact list and automatically sends the malicious link to new targets.

To stay hidden, the malware retrieves commands from a Gmail inbox using IMAP over SSL, a tactic that blends with normal user activity and bypasses many network defences. If that fails, it falls back to a hardcoded command-and-control address.

SpiderLabs described this approach as a “clever” method of maintaining persistence while evading detection or takedowns.

Brazil’s crypto boom draws cybercriminal attention

Brazil’s rapid surge in crypto adoption, ranking fifth on the Chainalysis Global Crypto Adoption Index and leading Latin America by trading volume, has made the nation an appealing target for financially motivated attackers. Interest has grown even further as the government explores plans for a national Bitcoin reserve and more robust regulatory frameworks.

This latest operation follows other recent threats. In September, Mosyle uncovered “ModStealer,” a cross-platform malware targeting browser wallet extensions on macOS, Windows, and Linux. Meanwhile, Google’s Threat Intelligence Group reported that malicious actors are now using AI to develop malware capable of rewriting its own code on the fly.

 

Take control of your crypto  portfolio with MARKETS PRO, DeFi Planet’s suite of analytics tools.”

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

Bitcoin Updates: Chicago Bitcoin ATM Sales—Expansion Plan or Result of DOJ Actions?

- Chicago-based Bitcoin ATM operator Crypto Dispensers explores a $100M sale amid federal money laundering charges against founder Firas Isa. - DOJ alleges the company processed $10M in illicit funds via ATMs, converting cash to crypto through untraceable wallets despite KYC obligations. - The firm shifts to software operations since 2020, citing rising compliance costs and fraud risks amid broader crypto market turbulence. - Isa faces up to 20 years in prison if convicted, while DOJ’s enforcement signals

Bitget-RWA2025/11/23 15:30
Bitcoin Updates: Chicago Bitcoin ATM Sales—Expansion Plan or Result of DOJ Actions?

Zcash News Today: Zcash's Rise in Privacy Poses a Challenge to Bitcoin's Reign of Transparency

- Zcash (ZEC) surged 150% in 30 days, outperforming crypto markets amid Cypherpunk's $18M ZEC investment boosting its $150M holdings. - Institutional demand for privacy coins like ZEC, Monero, and Dash grows as Zcash's 1.43% supply control tightens liquidity and drives $670+ prices. - Technical analysts project 40%+ gains if ZEC breaks $690, with Arthur Hayes predicting $1,000 potential, contrasting Bitcoin's $88k slump. - Zcash's November 2025 halving and privacy-focused narrative challenge Bitcoin's tran

Bitget-RWA2025/11/23 15:16
Zcash News Today: Zcash's Rise in Privacy Poses a Challenge to Bitcoin's Reign of Transparency

YFI Declines 49.94% Over the Past Year as Overall Market Faces Downturn

- YFI fell 0.15% in 24 hours to $4006, with 49.94% annual decline amid broader crypto market downturn. - Yearn.finance lacks project updates or governance changes to drive price recovery since November 2025. - Token remains vulnerable to macroeconomic shifts and geopolitical risks affecting risk-on/risk-off investor behavior. - Analysts expect continued consolidation until on-chain metrics show ecosystem improvements or external market confidence rebounds.

Bitget-RWA2025/11/23 15:10
YFI Declines 49.94% Over the Past Year as Overall Market Faces Downturn

Bessent: Raising the Debt Ceiling by July Is Essential to Prevent Market Turmoil

- US Treasury Secretary Bessent reiterated the economy is not at recession risk despite fiscal debates and market volatility. - He warned the debt ceiling must rise by July 2025 to avoid default, stressing "full faith and credit" is non-negotiable. - Corporate resilience (e.g., Ross Stores' strong earnings) contrasts with Fed policymakers' split on rate cuts amid inflation concerns. - Trump's $2,000 "tariff dividend" proposal faces congressional hurdles, with Bessent acknowledging it requires legislative a

Bitget-RWA2025/11/23 14:54
Bessent: Raising the Debt Ceiling by July Is Essential to Prevent Market Turmoil