A newly identified WhatsApp-based worm-and-trojan campaign in Brazil is compromising crypto wallets and bank accounts through a rapidly spreading malware cluster dubbed Eternidade.A newly identified WhatsApp-based worm-and-trojan campaign in Brazil is compromising crypto wallets and bank accounts through a rapidly spreading malware cluster dubbed Eternidade.

Brazil Faces Surge in WhatsApp Worm Attacks Targeting Crypto and Banking Apps

A newly identified WhatsApp-based worm-and-trojan campaign in Brazil is compromising crypto wallets and bank accounts through a rapidly spreading malware cluster dubbed Eternidade.

Researchers Identify New Multi-Stage Threat

Brazilian crypto users are being warned about an emerging malware operation that leverages WhatsApp hijacking to spread a banking trojan designed to harvest financial credentials. Trustwave SpiderLabs researchers have disclosed that the campaign revolves around a newly identified stealer known as Eternidade, a Delphi-based malware capable of dynamically updating its command-and-control infrastructure and stealthily collecting data from victims.

Researchers Nathaniel Morales, John Basmayor, and Nikita Kazymirskyi noted that WhatsApp remains central to Brazil’s cybercriminal ecosystem, stating, 

How the Infection Chain Works

According to the research team, the ongoing operation begins with social engineering messages delivered via WhatsApp. These lures mimic familiar formats, such as delivery notifications, fraudulent investment groups, and “fake government programs”, to trick recipients into clicking malicious links.

Once clicked, the link triggers the deployment of both a hijacking worm and the Eternidade banking trojan. The worm immediately takes control of the victim’s WhatsApp account, extracts the contact list, and selectively targets individual contacts using “smart filtering,” bypassing business groups to maximize the likelihood of personal engagement.

Simultaneously, a trojan file is silently downloaded on the device. This component installs the Eternidade Stealer in the background, enabling attackers to scan for credentials tied to major Brazilian banks, fintech platforms, and cryptocurrency exchanges and wallets.

Adaptive Command-and-Control via Gmail

One of the campaign’s most crucial traits is its unconventional method for receiving updated commands. Instead of relying on static server addresses, Eternidade uses hardcoded credentials to log into a Gmail account via IMAP. This allows the attackers to send updated instructions simply by emailing the controlled account.

The researchers highlighted this technique in their report: 

The Eternidade operation follows closely behind another Brazil-focused malware wave known as Water Saci, which used a WhatsApp Web worm called SORVEPOTEL to distribute Maverick, a .NET-based banking trojan linked to earlier Coyote malware variants. These incidents underscore a persistent trend in the region: the use of WhatsApp as a primary vector and the enduring reliance on Delphi-based tools for malware development.

Safety Recommendations

Security experts are advising WhatsApp users to avoid clicking unfamiliar links, even when sent by trusted contacts. Confirming suspicious messages through alternate communication channels is recommended, particularly when little context accompanies the link.

Disclaimer: This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice

Market Opportunity
SURGE Logo
SURGE Price(SURGE)
$0.08423
$0.08423$0.08423
-0.40%
USD
SURGE (SURGE) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Uniswap Gains Momentum While Pi Network Waits: Is BlockDAG At $0.001 The Best Crypto To Buy Now?

Uniswap Gains Momentum While Pi Network Waits: Is BlockDAG At $0.001 The Best Crypto To Buy Now?

The pi network price is seeking proof. A payments toolkit sounds meaningful, but markets reward usage over updates, and Pi […] The post Uniswap Gains Momentum While
Share
Coindoo2026/01/18 08:02
Academic Publishing and Fairness: A Game-Theoretic Model of Peer-Review Bias

Academic Publishing and Fairness: A Game-Theoretic Model of Peer-Review Bias

Exploring how biases in the peer-review system impact researchers' choices, showing how principles of fairness relate to the production of scientific knowledge based on topic importance and hardness.
Share
Hackernoon2025/09/17 23:15
Why This New Trending Meme Coin Is Being Dubbed The New PEPE After Record Presale

Why This New Trending Meme Coin Is Being Dubbed The New PEPE After Record Presale

The post Why This New Trending Meme Coin Is Being Dubbed The New PEPE After Record Presale appeared on BitcoinEthereumNews.com. Crypto News 17 September 2025 | 20:13 The meme coin market is heating up once again as traders look for the next breakout token. While Shiba Inu (SHIB) continues to build its ecosystem and PEPE holds onto its viral roots, a new contender, Layer Brett (LBRETT), is gaining attention after raising more than $3.7 million in its presale. With a live staking system, fast-growing community, and real tech backing, some analysts are already calling it “the next PEPE.” Here’s the latest on the Shiba Inu price forecast, what’s going on with PEPE, and why Layer Brett is drawing in new investors fast. Shiba Inu price forecast: Ecosystem builds, but retail looks elsewhere Shiba Inu (SHIB) continues to develop its broader ecosystem with Shibarium, the project’s Layer 2 network built to improve speed and lower gas fees. While the community remains strong, the price hasn’t followed suit lately. SHIB is currently trading around $0.00001298, and while that’s a decent jump from its earlier lows, it still falls short of triggering any major excitement across the market. The project includes additional tokens like BONE and LEASH, and also has ongoing initiatives in DeFi and NFTs. However, even with all this development, many investors feel the hype that once surrounded SHIB has shifted elsewhere, particularly toward newer, more dynamic meme coins offering better entry points and incentives. PEPE: Can it rebound or is the momentum gone? PEPE saw a parabolic rise during the last meme coin surge, catching fire on social media and delivering massive short-term gains for early adopters. However, like most meme tokens driven largely by hype, it has since cooled off. PEPE is currently trading around $0.00001076, down significantly from its peak. While the token still enjoys a loyal community, analysts believe its best days may be behind it unless…
Share
BitcoinEthereumNews2025/09/18 02:50