HomeSecurityHackers use WhatsApp to distribute SORVEPOTEL malware

Hackers use WhatsApp to distribute SORVEPOTEL malware

Corporate networks worldwide are facing a significant threat, a self-replicating malware that exploits WhatsApp as its primary delivery mechanism.

WhatsApp malware SORVEPOTEL

This campaign, first observed in early September 2025 and targeting organizations in Brazil, is spread via convincing phishing emails containing malicious ZIP attachments. Upon execution, the malware installs an access point on the system and actively hijacks WhatsApp Web sessions to replicate itself to all contacts and groups associated with the compromised account.

This unprecedented combination of social engineering and automated propagation has made SORVEPOTEL a significant threat to businesses that rely on messaging platforms for internal communication. Initial reports identified the campaign in phishing emails with file names such as RES-20250930112057.zip or ORCAMENTO114418.zip, which pretend to be innocent documents such as receipts or budgets. These emails urge users to “download the ZIP to their computer and open it,” explicitly targeting desktop sessions to maximize business impact.

See also: Malicious PyPI soopsocks package infected 2,653 systems

Trend Micro analysts have identified that an alternative infection route involves phishing emails that distribute similar ZIP attachments (often appearing to come from trusted organizations with subjects like “ComprovanteSantander-75319981.682657420.zip”). Once the ZIP is extracted, the victim encounters a deceptive Windows shortcut file (.LNK) designed to launch a hidden PowerShell script , which downloads and executes the main payload from domains controlled by the attackers.

SORVEPOTEL malware: Attack chain

When the .LNK file is executed, it triggers a coded command that launches a batch script in a hidden window. This attack chain depicts the encrypted command line within the shortcut that uses the PowerShell Invoke-Expression (IEX) with the -enc parameter to hide the payload. This script retrieves a secondary batch file payload and establishes a persistent presence by copying itself to the Windows Startup folder.

See also: Bug in Microsoft Defender for Endpoint causes false BIOS alerts

Hackers use WhatsApp to distribute SORVEPOTEL malware

Through a series of Base64 encoded PowerShell commands, the malware creates URLs that point to command and control (C2) servers and uses Net.WebClient to retrieve additional data, which is then executed in memory. The decrypted command within the batch file connects to the C2 infrastructure. Using typographical domains such as sorvetenopotel.com (a variation of the Portuguese phrase “sorvete no pote”), the attackers mix malicious traffic with legitimate network traffic, evading basic detection mechanisms.

Once a permanent presence is established, the malware scans for active WhatsApp Web sessions. Upon finding an authenticated session, SORVEPOTEL automatically replicates the same malicious ZIP to all contacts and groups. This automated spamming not only multiplies infection rates, but often leads to the suspension of compromised accounts for violating WhatsApp’s terms of service.

Hackers use WhatsApp to distribute SORVEPOTEL malware

Combining social engineering, script execution, and rapid session hijacking, SORVEPOTEL demonstrates a new escalation in attacks across messaging platforms. The malware’s focus on large-scale distribution (rather than direct data theft) underscores a shift toward maximizing reach and operational disruption.

See also: PoC released for critical vulnerability in VMware Workstation

Organizations should enforce strict endpoint policies to block unauthorized shortcuts , disable auto-download features in messaging apps, and conduct regular user training to mitigate the evolving risk posed by self-replicating threats like SORVEPOTEL

Extra malware protection tips

Static detection methods for security are not enough to avoid malware. A more robust approach should incorporate software antivirus, equipped with advanced analysis capabilities.

Information security training is also crucial. This means employees need to learn to recognize and avoid phishing attacks, which attackers often use to install malware.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

It's also important to keep your operating system and applications up to date. These updates often include security patches that can protect your computer from the latest threats.

Also, don't forget to use firewalls and monitor network traffic to help immediately detect suspicious activity. Users are also advised to avoid executable files downloaded from strange websites.

Finally, using strong passwords and enabling two-factor authentication can provide an extra layer of protection against malware. This can make it harder for attackers to gain access to your account , even if they manage to steal your password.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS