WhatsApp Weaponized in Brazil as New Malware Campaign Targets Crypto Users
Quick Breakdown
- Cybercriminals in Brazil are using WhatsApp to spread a worm and banking trojan that steals crypto and financial data.
- The malware hijacks WhatsApp sessions, scans devices for banking and wallet apps, and propagates through victim contact lists.
- Rising crypto adoption in Brazil is attracting sophisticated threats, including AI-powered malware and cross-platform stealers.
Cybercriminals in Brazil have launched a sophisticated malware operation that uses WhatsApp as the primary delivery channel to hijack devices and steal financial data, including access to crypto wallets.
🚨 A new WhatsApp worm is spreading fast in Brazil.
It hijacks chats, sends fake messages to all your contacts, and installs a program that steals bank and crypto logins.
… and it updates itself through an email inbox to stay hidden.
Read here ↓
— The Hacker News (@TheHackersNews) November 19, 2025
The discovery was made by Trustwave’s SpiderLabs, which identified the campaign deploying the “Eternidade Stealer,” a tool designed to quietly extract sensitive information from banking apps, fintech platforms, and crypto exchanges.
Social engineering fuels the infection chain
According to researchers, the attackers rely heavily on WhatsApp-based social engineering, sending victims messages disguised as government benefits, delivery updates, or investment opportunities. Once a user taps the malicious link, an automated sequence takes over, hijacking the victim’s WhatsApp session and downloading an MSI installer in the background.
This installer deploys a Delphi-based banking trojan that scans the device for financial applications such as Bradesco, BTG Pactual, Binance, Coinbase, MetaMask, and Trust Wallet. The moment it detects one of these applications, the malware decrypts and launches its next-stage payload.
Self-spreading worm and stealthy C2 communication
One of the campaign’s more alarming traits is its ability to spread itself. The worm accesses the victim’s WhatsApp contact list and automatically sends the malicious link to new targets.
To stay hidden, the malware retrieves commands from a Gmail inbox using IMAP over SSL, a tactic that blends with normal user activity and bypasses many network defences. If that fails, it falls back to a hardcoded command-and-control address.
SpiderLabs described this approach as a “clever” method of maintaining persistence while evading detection or takedowns.
Brazil’s crypto boom draws cybercriminal attention
Brazil’s rapid surge in crypto adoption, ranking fifth on the Chainalysis Global Crypto Adoption Index and leading Latin America by trading volume, has made the nation an appealing target for financially motivated attackers. Interest has grown even further as the government explores plans for a national Bitcoin reserve and more robust regulatory frameworks.
This latest operation follows other recent threats. In September, Mosyle uncovered “ModStealer,” a cross-platform malware targeting browser wallet extensions on macOS, Windows, and Linux. Meanwhile, Google’s Threat Intelligence Group reported that malicious actors are now using AI to develop malware capable of rewriting its own code on the fly.
Take control of your crypto portfolio with MARKETS PRO, DeFi Planet’s suite of analytics tools.”
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
XRP News Today: The Growth of Blockchain Real Estate May Position XRP as the Next Worldwide Benchmark
- Ledger Man's analysis links blockchain real estate systems to XRP's potential $79.73 surge, citing tokenization's market modernization potential. - New Jersey's 370,000 property records blockchain pilot and Dubai's XRP-based title deeds highlight government adoption of the technology. - BlackRock's $10T asset tokenization plans and McAllen's fractionalized $235K home demonstrate real-world blockchain applications in real estate. - XRP's regulatory partnerships and Netcapital's digital securities platform

XRP News Today: Crypto Market Splits: ETFs Gain Stability While Presales Remain Speculative
- New XRP and Dogecoin ETFs launch as U.S. regulatory approvals materialize, signaling institutional crypto adoption growth. - BNB outperforms XRP with stronger technical resilience and deflationary model, while XRP lags in cross-border utility growth. - Apeing’s presale gains traction as a high-risk 1000x return opportunity, contrasting with stable BNB and Litecoin dips. - Regulated ETFs and speculative presales highlight diverging investor strategies, with next 12–18 months shaping crypto’s new equilibri
Ethereum Updates Today: Ethereum ETFs Recover as Investors Weigh Immediate Fluctuations Against Future Improvements
- Ethereum spot ETFs recorded a $55.7M net inflow, led by FETH's 60% share, reflecting institutional confidence in post-upgrade fundamentals. - ETH/BTC ratio hit 0.052 (7-month low) as Bitcoin dominance rose to 53.2%, with Ethereum trading below key EMAs amid bearish technical indicators. - Upcoming Dencun upgrade (EIP-4844) and $7.4B+ real-world asset tokenization drive long-term optimism despite short-term volatility and higher ETF fees. - Staking infrastructure grows (Lido's 8.95M ETH, MAVAN network) wh

Bitcoin Updates: The Crypto Market Splits—Bitcoin ETFs See Outflows While Altcoin Enthusiasts Seek Returns and New Developments
- Bitcoin ETFs lost $3B in November, with BlackRock’s IBIT seeing $523M outflow as prices fell below $90K. - Bitwise’s Solana and XRP ETFs gained $580M and $420M inflows, offering staking rewards and cross-border payment exposure. - Institutional investors repositioned capital, shorting 53% of Bitcoin while Ethereum retained 55% long positions. - Analysts highlight altcoin ETFs’ yield advantages, but warn of Bitcoin’s liquidity risks and XRP’s weak derivatives market. - Market divergence reflects crypto-na

