Cyber threat hunters have discovered similarities between a banking malware called Coyote and a new malware program recently revealed called Maverick that spreads via WhatsApp.

According to a report from CyberProof , both malicious applications are written in .NET , target banks Brazilian users and , and have identical functionality for decryption, targeting banking URLs, and monitoring banking applications. Most importantly, both include the ability to spread via WhatsApp Web.
Maverick malware
Maverick was first documented by Trend Micro early last month. Researchers linked it to a threat actor called Water Saci. The campaign also includes a self-propagating malware referred to as SORVEPOTEL, which is spread via the desktop version of WhatsApp web and is used to deliver a ZIP file containing the Maverick payload.
The malware is designed to monitor active browser windows for URLs that match a hard-coded list of financial institutions in Latin America. If the URLs match, it initiates contact with a remote server to receive commands to collect system information and display phishing pages to steal credentials.
See also: Rhadamanthys infostealer: Sudden shutdown
Cybersecurity firm Sophos was the first to notice similarities to previous campaigns that spread Coyote targeting users in Brazil. In general, the question has been raised whether Maverick is an evolution of Coyote. Another analysis by Kaspersky found that Maverick contained many code overlaps with Coyote, but treats it as a completely new threat that targets Brazil en masse.
The latest findings from CyberProof show that the ZIP file contains a Windows shortcut (LNK) that, when launched by the user, runs cmd.exe or PowerShell to connect to an external server (“zapgrande[.]com”) and download the first-stage payload. The PowerShell script is capable of launching middleware designed to disable Microsoft Defender Antivirus and UAC, as well as retrieve a .NET loader.

The loader has analysis techniques to check for the presence of reverse engineering tools and terminates itself if found. The loader then proceeds to download the main attack modules: SORVEPOTEL and Maverick. It is worth noting here that Maverick is only installed after ensuring that the victim is located in Brazil, by checking the time zone, language, region, and date and time format of the infected computer.
See also: GootLoader: New hiding technique on WordPress websites
CyberProof also reported finding evidence of the malware being used to target hotels in Brazil (indicating a possible expansion of targeting).
New attack chain from Water Saci
The revelation comes as Trend Micro detailed Water Saci's new attack chain that uses an command and control (C2), relies on multi-vector persistence for resilience, and incorporates several advanced controls to evade detection, enhance operational stealth, and limit execution to only systems using the Portuguese language.
“The new attack chain features a sophisticated remote command and control system that allows threat actors to manage, pause, resume, and monitor the malware campaign, effectively turning infected machines into a botnet tool for coordinated, dynamic operations across multiple endpoints,” the company said last month.
The infection sequence uses Visual Basic Script (VB Script) and PowerShell to hijack WhatsApp browser sessions and spread the ZIP file via the messaging app. Similar to the previous attack chain, the WhatsApp Web takeover is accomplished by downloading ChromeDriver and Selenium for browser automation.
The attack is triggered when a user downloads and extracts the ZIP file, which includes an obfuscated VBS downloader (“Orcamento.vbs” also known as SORVEPOTEL), which, in turn, issues a PowerShell command to download and execute a PowerShell script (“tadeu.ps1”) directly into memory.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
This PowerShell script is used to take control of the victim’s WhatsApp Web session and distribute malicious ZIP files to all contacts associated with their account, while displaying a deceptive banner with the name “WhatsApp Automation v6.0” to hide its malicious intent. In addition, the script communicates with a C2 server to retrieve message templates and steal contact lists.
See also: Android Trojan 'Fantasy Hub' turns Telegram into a hub for hackers
“ After terminating any existing Chrome processes and deleting old sessions to ensure clean operation, the malware copies the victim’s legitimate Chrome profile data to its temporary workspace ,” Trend Micro said . “ This data includes cookies, authentication tokens, and the browser’s saved session .”
“This technique allows the malware to completely bypass WhatsApp Web authentication, gaining direct access to the victim's WhatsApp account without triggering security alerts or requiring a QR code scan“.
The malware also implements a sophisticated remote control mechanism that allows the attacker to pause, resume, and monitor progress in real time, effectively turning it into malware capable of controlling compromised hosts like a bot.

As for how it actually distributes the ZIP file, the PowerShell code iterates over each contact collected and checks for a pause command before sending personalized messages, replacing variables in the message template with time-based greetings and contact names.
Another important aspect of SORVEPOTEL is that it leverages IMAP connections to terra.com[.]br email accounts using hardcoded email credentials to connect to the email account and retrieve commands instead of using traditional HTTP-based communication. Some of these accounts have been secured using multi-factor authentication (MFA) to prevent unauthorized access.
This additional layer of security is said to have introduced operational delays, as each connection requires the threat actor to manually enter a one-time authentication code to access the inbox and store the C2 server URL (used to send the commands). The backdoor then periodically queries the C2 server to retrieve the command.
See also: Many people targeted by government spyware
The widespread nature of the campaign is due to the popularity of WhatsApp in Brazil, with the app having over 148 million active users.
“The infection methods and continued tactical evolution, along with the region-focused targeting, indicate that Water Saci is likely linked to Coyote, and that both campaigns operate within the same Brazilian cybercrime ecosystem,” Trend Micro said, describing the attackers as aggressive “in quantity and quality.”
