Cybersecurity researchers have revealed details of a new campaign that leverages a combination of social engineering and WhatsApp compromise to distribute a Delphi, known as Eternidade Stealer, in attacks targeting users in Brazil.
See also: WhatsApp is testing multiple account support

“It uses the Internet Message Access Protocol (IMAP) to dynamically retrieve command and control (C2) addresses, allowing the attacker to update their C2 server,” Trustwave SpiderLabs researchers Nathaniel Morales, John Basmayor , and Nikita Kazymirskyi in a technical analysis of the campaign shared with The Hacker News.
The findings come shortly after another campaign called Water Saci targeted Brazilian users with a worm spread via WhatsApp Web known as SORVEPOTEL, which then acts as a conduit for Maverick, a .NET believed to be an evolution of a .NET banking malware called Coyote.
The Eternidade Stealer cluster is part of a broader operation that has exploited WhatsApp's ubiquity in South America to compromise target systems and use the messaging app as a vector for launching large-scale attacks against Brazilian institutions.
Another notable trend is the continued preference for Delphi-based malware by attackers targeting Latin America, largely due not only to its technical efficiency but also to the fact that the programming language was taught and used in software development in the region.
The beginning of the attack is a garbled Visual Basic Script, which contains comments written mostly in Portuguese. The script, once executed, drops a batch script that is responsible for delivering two payloads, essentially splitting the infection chain into two:
1. A Python script that triggers the spread of malware via WhatsApp Web in a worm-like manner.
2. An MSI installer that uses an AutoIt script to launch Eternidade Stealer.
See also: WhatsApp Research Proxy: Meta's new tool for researchers

The Python script, similar to SORVEPOTEL, establishes communication with a remote server and leverages the open source WPPConnect to automate sending messages to compromised accounts via WhatsApp. To do this, it collects the victim's entire contact list, while filtering out groups, business contacts, and broadcast lists.
The malware then proceeds to collect, for each contact, the WhatsApp phone number, name, and information indicating whether it is a saved contact. This information is sent to a server controlled by the attacker via an HTTP POST. In the final stage, a malicious attachment is sent to all contacts in the form of a malicious attachment using a message template and filling in certain fields with time-based greetings and contact names.
The second leg of the attack begins with the MSI installer dropping various payloads, including an AutoIt script that checks if the compromised system is based in Brazil by looking to see if the operating system language is Brazilian Portuguese. If not, the malware terminates itself. This suggests a hyper-local targeting effort on the part of the attackers.
The script then scans running processes and registry keys for the presence of installed security products. It also profiles the machine and sends the details to a command and control (C2) server. The attack culminates with the malware injecting the Eternidade Stealer payload into “svchost.exe” using the empty process technique.
See also: WhatsApp vulnerability exposed 3.5 billion phone numbers
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

A Delphi-based credential stealer, Eternidade constantly scans active windows and running processes for strings related to banking portals, payment services, and cryptocurrency exchanges and wallets, including Bradesco, BTG Pactual, MercadoPago, Stripe, Binance, Coinbase, MetaMask, and Trust Wallet.
