Brazilian Campaign: Spreading the Malware via WhatsApp
Dec. 21, 2025, 5:59 p.m.
Description
A massive phishing campaign targeting Brazil is spreading malware through WhatsApp Web using an open-source automation script and loading a banking trojan into memory. The attack begins with a phishing email containing a malicious VBS script that downloads and executes an MSI file and another VBS file. The second VBS installs Python and Selenium, which are used to inject malicious JavaScript into WhatsApp Web. This allows the malware to send itself to the victim's contacts. The MSI file drops an AutoIt script that monitors for Brazilian banking and cryptocurrency-related windows, then loads an encrypted payload into memory to avoid detection. The payload targets specific Brazilian financial institutions and cryptocurrency wallets.
Tags
Date
- Created: Nov. 24, 2025, 12:02 p.m.
- Published: Nov. 24, 2025, 12:02 p.m.
- Modified: Dec. 21, 2025, 5:59 p.m.
Indicators
- 559de79e8aa9be8b64c77543e0a2e74494ead20a0f499e25d45a0fed3ad7352a
- 5e41ab0d45b7046d6fef9ac01d1fc0df8bdeb60227edf40f8e351c60b09b8b7d
- 2c885d1709e2ebfcaa81e998d199b29e982a7559b9d72e5db0e70bf31b183a5f
- 6168d63fad22a4e5e45547ca6116ef68bb5173e17e25fd1714f7cc1e4f7b41e1
Additional Informations
- Finance
- varegjopeaks.com
- Brazil