Brazilian Campaign: Spreading the Malware via WhatsApp

Nov. 24, 2025, 12:41 p.m.

Description

A massive phishing campaign targeting Brazil is spreading malware through WhatsApp Web using an open-source automation script and loading a banking trojan into memory. The attack begins with a phishing email containing a malicious VBS script that downloads and executes an MSI file and another VBS file. The second VBS installs Python and Selenium, which are used to inject malicious JavaScript into WhatsApp Web. This allows the malware to send itself to the victim's contacts. The MSI file drops an AutoIt script that monitors for Brazilian banking and cryptocurrency-related windows, then loads an encrypted payload into memory to avoid detection. The payload targets specific Brazilian financial institutions and cryptocurrency wallets.

Date

  • Created: Nov. 24, 2025, 12:02 p.m.
  • Published: Nov. 24, 2025, 12:02 p.m.
  • Modified: Nov. 24, 2025, 12:41 p.m.

Indicators

  • 559de79e8aa9be8b64c77543e0a2e74494ead20a0f499e25d45a0fed3ad7352a
  • 5e41ab0d45b7046d6fef9ac01d1fc0df8bdeb60227edf40f8e351c60b09b8b7d
  • 6168d63fad22a4e5e45547ca6116ef68bb5173e17e25fd1714f7cc1e4f7b41e1
  • 2c885d1709e2ebfcaa81e998d199b29e982a7559b9d72e5db0e70bf31b183a5f
  • varegjopeaks.com

Attack Patterns

Additional Informations

  • Finance
  • Brazil