Security researchers have identified a sophisticated malware campaign that exploits the WhatsApp to deploy banking trojans targeting Brazilian financial institutions and cryptocurrency exchanges.

It is a self-replicating worm, which appeared on September 29, 2025, and demonstrates advanced evasion techniques and multi-layered infection chains, designed to bypass modern security defenses. The threat has already affected over 400 customer environments on more than 1,000 endpoints, highlighting the broad reach and effectiveness of the campaign.
See also: Banking trojan Astaroth abuses GitHub
The attack begins when victims receive a malicious ZIP file via WhatsApp Web from an already infected contact. The social engineering element is particularly clever, as the message claims that the attached content can only be viewed on a computer, effectively forcing recipients to download and execute the malware on desktop systems instead of mobile devices. This strategic approach ensures that the malware operates in an environment where it can establish persistence and fully deploy its payload capabilities.
Sophos analysts identified the sophisticated malware infection mechanism during their investigation of multiple incidents in Brazil. The perpetrators demonstrate a deep understanding of the Windows security architecture and PowerShell capabilities , implementing obfuscation techniques that allow the malware to operate undetected for extended periods. The technical sophistication of the campaign suggests the involvement of experienced cybercriminals with significant resources and knowledge of Brazilian banking systems.

WhatsApp Abuse: Multi‑layered Infection Chain
The malware execution begins with a LNK file Windows hidden within the ZIP archive. When executed, the LNK file contains an encrypted Windows command that constructs and executes a Base64-encoded PowerShell. This first stage of the PowerShell script secretly launches an Explorer process that downloads the next stage payload from command and control servers.
See also: Android banking trojan uses VNC server to remotely control devices
The second-stage PowerShell command demonstrates the malware’s ability to evade detection through explicit security control modifications. Portuguese-language comments embedded in the PowerShell code reveal the author’s intentions to “ add an exception to Microsoft Defender ” and “ disable UAC ” (User Account Control). These modifications create an environment where the malware can operate without triggering security alerts or requiring user interaction for privileged operations.
The campaign delivers two distinct payloads depending on the characteristics of the infected system: a legitimate Selenium browser automation tool with a corresponding ChromeDriver and a banking trojan named Maverick.
The Selenium payload allows attackers to control active browser sessions, facilitating WhatsApp web session hijacking and enabling the worm's self-replication mechanism. Meanwhile, the Maverick banking trojan monitors browser traffic for connections to Brazilian banks and cryptocurrency exchanges, deploying additional .NET-based malware when financial targets are reached.
See also: Android banking trojans mimic government apps

Protection from banking trojan
- Installing antivirus software is essential for protecting your device. These software can identify and remove malware before it can cause damage.
- It's important to keep your operating system and applications up to date. Updates often include security fixes that can protect your device from malware.
- Avoid installing apps from third-party sources. These apps have not undergone the same security checks as those in official stores.
- Pay attention to the permissions apps ask for. If an app asks for access to personal information that doesn't seem necessary, it may be best not to install it.
- Be wary of phishing messages that may try to trick you into downloading malware. These messages may appear to come from legitimate sources, but they often contain links or attachments that can install malware on your device.
- Use strong passwords and implement multi-factor authentication (MFA) where possible.
- Finally, it's important to regularly back up your data. This can help restore your information if your device is infected with malware.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
