The post Brazilian crypto users hit by WhatsApp malware campaign targeting crypto wallets appeared on BitcoinEthereumNews.com. Bad actors are weaponizing WhatsApp to deliver a hijacking worm and banking trojan in Brazil that targets their crypto wallets. Summary SpiderLabs has warned about a WhatsApp‑based malware campaign in Brazil that deploys a worm and banking trojan to target crypto users. The malware is able to harvest sensitive information related to the victim’s crypto exchange account and wallets. Trustwave’s cybersecurity research team SpiderLabs has uncovered a major campaign involving the Eternidade Stealer, which can quietly harvest financial information, login data, and other sensitive details associated with banking portals, fintech apps, and crypto exchanges on the victim’s device. Threat actors were found to be using complex social engineering schemes involving “fake government programs, delivery notifications, and even fraudulent investment groups shared through WhatsApp messages and groups,” the report said. Attackers are using a two‑stage process to deliver the malicious payload that includes a WhatsApp‑propagating worm and a Delphi‑based banking trojan. When the victim clicks a worm link, it triggers an automated sequence that hijacks the WhatsApp session, downloads the MSI installer in the background, and deploys the stealer that scans for financial applications and crypto wallets. “When it detects a match, for example, a window title or process name linked to Bradesco, BTG Pactual, Binance, Coinbase, MetaMask, Trust Wallet, or another financial brand, the malware immediately decrypts and activates its next-stage payload,” Spiderlabs researchers explained. Another concerning trait of the campaign, besides its stealthy nature, is that the worm is able to access the victim’s contact list, which lets it target other potential victims. Meanwhile, it prevents detection by using “hardcoded credentials to log into its email account,” which is retrieved from a Gmail inbox controlled by the operator. By using IMAP over SSL to fetch commands, a method that blends with ordinary user email traffic, the malware is able… The post Brazilian crypto users hit by WhatsApp malware campaign targeting crypto wallets appeared on BitcoinEthereumNews.com. Bad actors are weaponizing WhatsApp to deliver a hijacking worm and banking trojan in Brazil that targets their crypto wallets. Summary SpiderLabs has warned about a WhatsApp‑based malware campaign in Brazil that deploys a worm and banking trojan to target crypto users. The malware is able to harvest sensitive information related to the victim’s crypto exchange account and wallets. Trustwave’s cybersecurity research team SpiderLabs has uncovered a major campaign involving the Eternidade Stealer, which can quietly harvest financial information, login data, and other sensitive details associated with banking portals, fintech apps, and crypto exchanges on the victim’s device. Threat actors were found to be using complex social engineering schemes involving “fake government programs, delivery notifications, and even fraudulent investment groups shared through WhatsApp messages and groups,” the report said. Attackers are using a two‑stage process to deliver the malicious payload that includes a WhatsApp‑propagating worm and a Delphi‑based banking trojan. When the victim clicks a worm link, it triggers an automated sequence that hijacks the WhatsApp session, downloads the MSI installer in the background, and deploys the stealer that scans for financial applications and crypto wallets. “When it detects a match, for example, a window title or process name linked to Bradesco, BTG Pactual, Binance, Coinbase, MetaMask, Trust Wallet, or another financial brand, the malware immediately decrypts and activates its next-stage payload,” Spiderlabs researchers explained. Another concerning trait of the campaign, besides its stealthy nature, is that the worm is able to access the victim’s contact list, which lets it target other potential victims. Meanwhile, it prevents detection by using “hardcoded credentials to log into its email account,” which is retrieved from a Gmail inbox controlled by the operator. By using IMAP over SSL to fetch commands, a method that blends with ordinary user email traffic, the malware is able…

Brazilian crypto users hit by WhatsApp malware campaign targeting crypto wallets

2025/11/20 17:10
Okuma süresi: 4 dk

Bad actors are weaponizing WhatsApp to deliver a hijacking worm and banking trojan in Brazil that targets their crypto wallets.

Summary

  • SpiderLabs has warned about a WhatsApp‑based malware campaign in Brazil that deploys a worm and banking trojan to target crypto users.
  • The malware is able to harvest sensitive information related to the victim’s crypto exchange account and wallets.

Trustwave’s cybersecurity research team SpiderLabs has uncovered a major campaign involving the Eternidade Stealer, which can quietly harvest financial information, login data, and other sensitive details associated with banking portals, fintech apps, and crypto exchanges on the victim’s device.

Threat actors were found to be using complex social engineering schemes involving “fake government programs, delivery notifications, and even fraudulent investment groups shared through WhatsApp messages and groups,” the report said.

Attackers are using a two‑stage process to deliver the malicious payload that includes a WhatsApp‑propagating worm and a Delphi‑based banking trojan. When the victim clicks a worm link, it triggers an automated sequence that hijacks the WhatsApp session, downloads the MSI installer in the background, and deploys the stealer that scans for financial applications and crypto wallets.

“When it detects a match, for example, a window title or process name linked to Bradesco, BTG Pactual, Binance, Coinbase, MetaMask, Trust Wallet, or another financial brand, the malware immediately decrypts and activates its next-stage payload,” Spiderlabs researchers explained.

Another concerning trait of the campaign, besides its stealthy nature, is that the worm is able to access the victim’s contact list, which lets it target other potential victims.

Meanwhile, it prevents detection by using “hardcoded credentials to log into its email account,” which is retrieved from a Gmail inbox controlled by the operator. By using IMAP over SSL to fetch commands, a method that blends with ordinary user email traffic, the malware is able to bypass network filters and remain difficult to trace.

“It is a very clever way to update its C2, maintain persistence, and evade detections or takedowns on a network level. If the malware cannot connect to the email account, it uses a hardcoded fallback C2 address,” researchers added.

SpiderLabs researchers have urged Brazilian crypto users to remain alert, especially on WhatsApp, which has become a favored tool for social engineering-based malware campaigns.

“WhatsApp continues to be one of the most exploited communication channels in Brazil’s cybercrime ecosystem. Over the past two years, threat actors have refined their tactics, using the platform’s immense popularity to distribute banker trojans and information-stealing malware,” researchers warned.

Crypto adoption in Brazil has soared over the past few years, and with recent developments like potential plans to establish a national Bitcoin reserve and enforce a proper regulatory framework, the country has drawn increased attention from global investors and local users alike. On the Chainalysis Global Crypto Adoption Index, Brazil ranks fifth, while it stands as Latin America’s largest crypto market by volume.

As such, it remains a prime target for scammers and other bad actors seeking to exploit inexperienced users or take advantage of poorly protected systems.

Eternidade Stealer is a kind of infostealer, which, as mentioned above, can silently monitor applications, extract sensitive credentials, and activate fake overlays to harvest user data..

Back in September, security platform Mosyle uncovered one such cross-platform threat called ModStealer that remained undetected for weeks and was found to be targeting crypto wallets across macOS, Windows, and Linux environments. By using obfuscated JavaScript code within a Node.js environment, the malware was able to infiltrate developer systems and exfiltrate private keys and clipboard data from over 50 browser wallet extensions.

More recently, a Google Threat Intelligence Group report warned that bad actors have started using artificial intelligence to develop malware that can rewrite its own code in real time, making it a lot harder to detect or neutralize.

Source: https://crypto.news/brazilian-crypto-users-hit-by-whatsapp-malware-campaign-targeting-crypto-wallets/

Piyasa Fırsatı
Bad Idea AI Logosu
Bad Idea AI Fiyatı(BAD)
$0.00000000095
$0.00000000095$0.00000000095
-4.04%
USD
Bad Idea AI (BAD) Canlı Fiyat Grafiği
Sorumluluk Reddi: Bu sitede yeniden yayınlanan makaleler, halka açık platformlardan alınmıştır ve yalnızca bilgilendirme amaçlıdır. MEXC'nin görüşlerini yansıtmayabilir. Tüm hakları telif sahiplerine aittir. Herhangi bir içeriğin üçüncü taraf haklarını ihlal ettiğini düşünüyorsanız, kaldırılması için lütfen service@support.mexc.com ile iletişime geçin. MEXC, içeriğin doğruluğu, eksiksizliği veya güncelliği konusunda hiçbir garanti vermez ve sağlanan bilgilere dayalı olarak alınan herhangi bir eylemden sorumlu değildir. İçerik, finansal, yasal veya diğer profesyonel tavsiye niteliğinde değildir ve MEXC tarafından bir tavsiye veya onay olarak değerlendirilmemelidir.

Ayrıca Şunları da Beğenebilirsiniz

White House meeting could unfreeze the crypto CLARITY Act this week, but crypto rewards likely to be the price

White House meeting could unfreeze the crypto CLARITY Act this week, but crypto rewards likely to be the price

White House stablecoin meeting could unfreeze the CLARITY Act, but your USDC rewards may be the price The newly confirmed Feb. 10 White House meeting on stablecoin
Paylaş
CryptoSlate2026/02/09 18:48
Coral Protocol launches Coral V1, introducing on-chain Solana payments for devs

Coral Protocol launches Coral V1, introducing on-chain Solana payments for devs

Coral Protocol has launched Coral V1, a new remote agent system that simplifies multi-agent software deployment. Developers building on the project now have production-ready agents that can be rented, customized, and combined with local solutions.  According to a press statement shared with Cryptopolitan on Friday, the platform introduces new capabilities to accelerate artificial intelligence (AI) […]
Paylaş
Cryptopolitan2025/09/19 20:01
U.S. Senate panel to hold crypto tax policy hearing on October 1

U.S. Senate panel to hold crypto tax policy hearing on October 1

The Senate Banking Committee will hold a public hearing on October 1 to go after one of the most confusing messes in U.S. finance right now:- how crypto gets taxed. The committee confirmed the date in a notice first reported by Eleanor Terrett, and witnesses lined up include Jason Somensatto, Policy Director at Coin Center; Andrea S. Kramer, founding member of ASKramer Law; Lawrence Zlatkin, Vice President of Taxation at Coinbase; and Annette Nellen, Chair of the Digital Asset Taxation Working Group under the American Institute of Certified Public Accountants. This hearing is meant to address a problem that’s pissed off crypto users for years, which is why every small crypto transaction, even a few dollars, triggers a tax headache. The Senate is being pushed to finally look at de minimis exemptions, which would let people use crypto for daily stuff (like grabbing a coffee) without reporting every damn thing to the IRS. Trump administration backs small crypto tax relief Cryptopolitan reported back in July that White House Press Secretary Karoline Leavitt had said that the Trump administration still wants to push through the de minimis exemption in upcoming laws. “The president did signal his support for de minimis exemption for crypto and the administration continues to be in support of that,” Karoline said. She explained that right now, using crypto for basic purchases is too complicated because of tax rules, but a change could make everyday payments smoother. “We are definitely receptive to it to make crypto payments easier and more efficient for those who seek to use crypto as simple as buying a cup of coffee — of course, right now, that cannot happen, but with the de minimis exemption perhaps it could in the future.” Karoline also revealed that President Trump plans to host a signing ceremony for the GENIUS Act, a stablecoin-focused bill expected to pass soon. That bill is part of his administration’s broader goal to make the U.S. “the crypto capital of the world.” The Senate has already tried and failed to deal with this issue before. In 2020, two Democratic lawmakers proposed the Virtual Currency Tax Fairness Act, which aimed to ignore tax on crypto gains below $200. It didn’t even make it to a vote. A similar version in 2022 also died on the floor. Then came a broader bill in 2025 called the One Big Beautiful Bill Act, which covered everything from taxes to border control. Senator Cynthia Lummis, a Republican from Wyoming, tried to get a crypto exemption added in for gains under $300, but that proposal got scrapped before the final bill passed. President Trump signed it into law on July 4 without the crypto language attached. Right now, the IRS says every single crypto transaction must be reported, even if there’s no gain or the amount is tiny. If you spend $5 of bitcoin, that’s a taxable event. The idea behind the de minimis exemption is to cut through that nonsense and give users room to breathe. But it hasn’t been easy. Lawmakers face real obstacles. First, the federal government depends on tax income. If it suddenly lets millions of small crypto transactions go untaxed, that means less money coming in. And there’s no sign yet of how they’ll offset that shortfall. Even with strong voices like Cynthia and Jason in the room, the Senate still hasn’t landed on a solution. October 1 might give them a chance to do something useful. Or it might be another meeting where everyone talks and nothing happens. Get seen where it counts. Advertise in Cryptopolitan Research and reach crypto’s sharpest investors and builders.
Paylaş
Coinstats2025/09/25 09:51