A new WhatsApp malware targets Brazilian users, stealing banking and crypto data while spreading through hijacked contacts. A fast-moving malware campaign is targeting WhatsApp users across Brazil.  This “WhatsApp Worm” has been discovered spreading through hijacked accounts and tricking people into opening harmful files. Once inside a device, it steals banking and crypto information, copies […] The post Crypto News: WhatsApp Malware Campaign Hits Brazilian Users Hard appeared first on Live Bitcoin News.A new WhatsApp malware targets Brazilian users, stealing banking and crypto data while spreading through hijacked contacts. A fast-moving malware campaign is targeting WhatsApp users across Brazil.  This “WhatsApp Worm” has been discovered spreading through hijacked accounts and tricking people into opening harmful files. Once inside a device, it steals banking and crypto information, copies […] The post Crypto News: WhatsApp Malware Campaign Hits Brazilian Users Hard appeared first on Live Bitcoin News.

Crypto News: WhatsApp Malware Campaign Hits Brazilian Users Hard

2025/11/20 22:45
4 min read
For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

A new WhatsApp malware targets Brazilian users, stealing banking and crypto data while spreading through hijacked contacts.

A fast-moving malware campaign is targeting WhatsApp users across Brazil. 

This “WhatsApp Worm” has been discovered spreading through hijacked accounts and tricking people into opening harmful files. Once inside a device, it steals banking and crypto information, copies contacts and continues its spread through new victims. 

Researchers warn that the malware uses updated methods that make it harder to detect or block.

How the WhatsApp Malware Campaign Starts

Attackers typically start their campaign through simple messages where they send fake alerts about government aid, package deliveries or investment groups. 

Some messages look like they came from friends or family, and victims are tricked into tapping a link and setting off a chain reaction.

The attack starts with a small script that silently downloads two main files. One controls the spread of the worm, while the other installs the banking trojan known as Eternidade Stealer. 

Brazil’s cybersecurity teams are warning users about a malware campaign spreading through WhatsApp | Brazil’s cybersecurity teams are warning users about a malware campaign spreading through WhatsApp source: X

The script includes Portuguese comments and checks for a Brazilian Portuguese system. If it does not find one, it shuts down. This shows the attackers aim at local victims, not global ones.

Attackers also switched from older PowerShell methods to a Python script. This script works through WhatsApp Web and uses WPPConnect to automate sending messages. 

It copies the victim’s full contact list. It also skips business accounts and groups to focus on people who are more likely to trust the sender.

How the Worm Hijacks WhatsApp Accounts

Once active, the worm takes over the victim’s WhatsApp session. It collects phone numbers, names and details that show whether someone is a saved contact. 

It then sends this information to a server controlled by the attackers. 

After doing this, the worm sends out a malicious file to all contacts. It uses a short template message, often with a greeting that matches the time of day. 

Many people trust these messages because they appear to come from someone they know and this helps the malware spread through families, friends and coworkers.

The campaign resembles another recent attack on Brazilian users known as Water Saci. 

That attack also spread through WhatsApp Web and delivered a similar banking trojan. The pattern of these hack attempts indicates that they are coming from active groups working in Brazil, and this group is refining the same methods across many campaigns.

Related Read: Federal Police Seize Cryptos from WhatsApp Hackers in Argentina

What the Eternidade Stealer Does After Infection

The Trojan that comes with the worm is the main threat. It runs in the background and scans the computer for open windows, processes and browser tabs. When it notices a banking or crypto service, it activates.

Eternidade Stealer searches for login screens from banks like Bradesco and BTG Pactual. It also checks for fintech services like MercadoPago and Stripe. 

It looks for crypto services too, including Binance, Coinbase, MetaMask and Trust Wallet. When it spots a match, it begins recording keystrokes, taking screenshots or stealing saved files.

The malware even uses a unique method to avoid shutdowns and does not rely on a fixed server. Instead, it logs into a pre-set email inbox using hardcoded credentials. 

It reads the inbox for new commands from the attackers. If the inbox fails, it returns to a backup server address. This setup helps the malware survive changes or takedowns.

Researchers found that the attackers run panels to manage infected devices. They monitor where victims are located and block almost all traffic that does not come from Brazil or Argentina. 

This is what keeps their servers from attracting attention.

The post Crypto News: WhatsApp Malware Campaign Hits Brazilian Users Hard appeared first on Live Bitcoin News.

Market Opportunity
ConstitutionDAO Logo
ConstitutionDAO Price(PEOPLE)
$0.006463
$0.006463$0.006463
-1.07%
USD
ConstitutionDAO (PEOPLE) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Best Crypto to Buy as Saylor & Crypto Execs Meet in US Treasury Council

Best Crypto to Buy as Saylor & Crypto Execs Meet in US Treasury Council

The post Best Crypto to Buy as Saylor & Crypto Execs Meet in US Treasury Council appeared on BitcoinEthereumNews.com. Michael Saylor and a group of crypto executives met in Washington, D.C. yesterday to push for the Strategic Bitcoin Reserve Bill (the BITCOIN Act), which would see the U.S. acquire up to 1M $BTC over five years. With Bitcoin being positioned yet again as a cornerstone of national monetary policy, many investors are turning their eyes to projects that lean into this narrative – altcoins, meme coins, and presales that could ride on the same wave. Read on for three of the best crypto projects that seem especially well‐suited to benefit from this macro shift:  Bitcoin Hyper, Best Wallet Token, and Remittix. These projects stand out for having a strong use case and high adoption potential, especially given the push for a U.S. Bitcoin reserve.   Why the Bitcoin Reserve Bill Matters for Crypto Markets The strategic Bitcoin Reserve Bill could mark a turning point for the U.S. approach to digital assets. The proposal would see America build a long-term Bitcoin reserve by acquiring up to one million $BTC over five years. To make this happen, lawmakers are exploring creative funding methods such as revaluing old gold certificates. The plan also leans on confiscated Bitcoin already held by the government, worth an estimated $15–20B. This isn’t just a headline for policy wonks. It signals that Bitcoin is moving from the margins into the core of financial strategy. Industry figures like Michael Saylor, Senator Cynthia Lummis, and Marathon Digital’s Fred Thiel are all backing the bill. They see Bitcoin not just as an investment, but as a hedge against systemic risks. For the wider crypto market, this opens the door for projects tied to Bitcoin and the infrastructure that supports it. 1. Bitcoin Hyper ($HYPER) – Turning Bitcoin Into More Than Just Digital Gold The U.S. may soon treat Bitcoin as…
Share
BitcoinEthereumNews2025/09/18 00:27
One Of Frank Sinatra’s Most Famous Albums Is Back In The Spotlight

One Of Frank Sinatra’s Most Famous Albums Is Back In The Spotlight

The post One Of Frank Sinatra’s Most Famous Albums Is Back In The Spotlight appeared on BitcoinEthereumNews.com. Frank Sinatra’s The World We Knew returns to the Jazz Albums and Traditional Jazz Albums charts, showing continued demand for his timeless music. Frank Sinatra performs on his TV special Frank Sinatra: A Man and his Music Bettmann Archive These days on the Billboard charts, Frank Sinatra’s music can always be found on the jazz-specific rankings. While the art he created when he was still working was pop at the time, and later classified as traditional pop, there is no such list for the latter format in America, and so his throwback projects and cuts appear on jazz lists instead. It’s on those charts where Sinatra rebounds this week, and one of his popular projects returns not to one, but two tallies at the same time, helping him increase the total amount of real estate he owns at the moment. Frank Sinatra’s The World We Knew Returns Sinatra’s The World We Knew is a top performer again, if only on the jazz lists. That set rebounds to No. 15 on the Traditional Jazz Albums chart and comes in at No. 20 on the all-encompassing Jazz Albums ranking after not appearing on either roster just last frame. The World We Knew’s All-Time Highs The World We Knew returns close to its all-time peak on both of those rosters. Sinatra’s classic has peaked at No. 11 on the Traditional Jazz Albums chart, just missing out on becoming another top 10 for the crooner. The set climbed all the way to No. 15 on the Jazz Albums tally and has now spent just under two months on the rosters. Frank Sinatra’s Album With Classic Hits Sinatra released The World We Knew in the summer of 1967. The title track, which on the album is actually known as “The World We Knew (Over and…
Share
BitcoinEthereumNews2025/09/18 00:02
Vistra (VST) Stock Drops 7% as Insider Sales Spook the Market

Vistra (VST) Stock Drops 7% as Insider Sales Spook the Market

TLDR Vistra (VST) stock fell as much as 7.16% as investors reacted to heavy insider selling by the CEO and top executives filed with the SEC. The stock also hit
Share
Coincentral2026/03/21 01:25