{"id":59561,"date":"2025-11-20T18:01:31","date_gmt":"2025-11-20T18:01:31","guid":{"rendered":"https:\/\/dogewisperer.com\/?p=59561"},"modified":"2025-11-20T18:01:31","modified_gmt":"2025-11-20T18:01:31","slug":"brazil-on-alert-whatsapp-malware-attacks-crypto-wallets-and-bank-accounts","status":"publish","type":"post","link":"https:\/\/dogewisperer.com\/?p=59561","title":{"rendered":"Brazil On Alert: WhatsApp Malware Attacks Crypto Wallets And Bank Accounts"},"content":{"rendered":"<div>\n<p>A new WhatsApp worm is sweeping through Brazil, stealing bank logins and crypto keys from ordinary users, security firms warn.<\/p>\n<p>Victims get a message that looks familiar \u2014 a delivery note, a government alert, or an invite to a group \u2014 and one click can let the threat spread through their contacts while a hidden trojan strips data from their machines.<\/p>\n<h2>How The Worm Spreads<\/h2>\n<p>According to security <a href=\"https:\/\/www.trustwave.com\/en-us\/resources\/blogs\/spiderlabs-blog\/spiderlabs-ids-new-banking-trojan-distributed-through-whatsapp\/\" target=\"_blank\" rel=\"noopener nofollow\">reports<\/a>, attackers send ZIP files over WhatsApp that contain a malicious .LNK shortcut. When opened, that shortcut runs deceptive commands which load more code into memory so little is written to the hard drive.<\/p>\n<p>This \u201cfileless\u201d step helps the malware avoid some antivirus tools. Based on reports, the infection also hijacks WhatsApp Web sessions to send the same bait to the victim\u2019s friends, making the attack behave like a worm.<\/p>\n<p><img data-recalc-dims=\"1\" fetchpriority=\"high\" decoding=\"async\" class=\"aligncenter size-full wp-image-631208\" src=\"https:\/\/bitcoinist.com\/wp-content\/uploads\/2025\/11\/A_98cef6.png?resize=633%2C304\" alt=\"\" width=\"633\" height=\"304\" srcset=\"https:\/\/bitcoinist.com\/wp-content\/uploads\/2025\/11\/A_98cef6.png?w=633 633w, https:\/\/bitcoinist.com\/wp-content\/uploads\/2025\/11\/A_98cef6.png?w=130 130w\" sizes=\"(max-width: 633px) 100vw, 633px\"><\/p>\n<p>One analyst group said more than 400 \u201ccustomer environments\u201d and over 1,000 endpoints showed signs of compromise, while another firm blocked roughly 62,000 infection attempts in the first 10 days of October.<\/p>\n<h2>Targets And Techniques<\/h2>\n<p>Reports have disclosed two main strains that are active in Brazil. One is a banking <a href=\"https:\/\/www.fortinet.com\/resources\/cyberglossary\/trojan-horse-virus\" target=\"_blank\" rel=\"noopener nofollow\">trojan<\/a> called Eternidade Stealer that uses a Gmail account as a hidden command channel.<\/p>\n<p><img loading=\"lazy\" data-recalc-dims=\"1\" decoding=\"async\" class=\"aligncenter size-full wp-image-631209\" src=\"https:\/\/bitcoinist.com\/wp-content\/uploads\/2025\/11\/A_0ee946.png?resize=733%2C737\" alt=\"\" width=\"733\" height=\"737\" srcset=\"https:\/\/bitcoinist.com\/wp-content\/uploads\/2025\/11\/A_0ee946.png?w=733 733w, https:\/\/bitcoinist.com\/wp-content\/uploads\/2025\/11\/A_0ee946.png?w=418 418w, https:\/\/bitcoinist.com\/wp-content\/uploads\/2025\/11\/A_0ee946.png?w=656 656w, https:\/\/bitcoinist.com\/wp-content\/uploads\/2025\/11\/A_0ee946.png?w=148 148w, https:\/\/bitcoinist.com\/wp-content\/uploads\/2025\/11\/A_0ee946.png?w=64 64w, https:\/\/bitcoinist.com\/wp-content\/uploads\/2025\/11\/A_0ee946.png?w=75 75w\" sizes=\"auto, (max-width: 733px) 100vw, 733px\"><\/p>\n<p>The other, known as Maverick, relies on automation tools such as WPPConnect to operate WhatsApp Web and to push malicious messages from infected accounts.<\/p>\n<p>The threats look for local settings before fully activating, checking timezone and language so the code runs mainly on machines set to Brazil.<\/p>\n<p>Security researchers say the <a href=\"https:\/\/www.cisco.com\/site\/us\/en\/learn\/topics\/security\/what-is-malware.html\" target=\"_blank\" rel=\"noopener nofollow\">malware<\/a> can snapshot screens, log keystrokes, and overlay fake login pages on banking or exchange websites.<\/p>\n<p>The list of targets is wide: it includes 26 Brazilian banks, six crypto exchanges, and one payment platform.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full\" src=\"https:\/\/www.tradingview.com\/x\/NT7Pa99V\/\" width=\"1835\" height=\"883\"><\/p>\n<p>Smart Filtering Makes It Worse<\/p>\n<p>The attackers appear to avoid business or group contacts. That choice seems designed to keep messages within small personal circles and to reduce early detection.<\/p>\n<p>Once a contact family or friend opens the link, the same cycle can repeat. Because the worm spreads by using trusted accounts, people are more likely to fall for the bait.<\/p>\n<p>The use of widely available services like Gmail for control instructions makes it harder for defenders to block a single command server.<\/p>\n<p>What To Do If You\u2019re Exposed<\/p>\n<p>According to security experts, if funds are at risk, act fast. Freeze or lock accounts when possible, alert your exchange or bank, and report the incident to local authorities.<\/p>\n<p>Enable strong multi-factor authentication on every financial account and use withdrawal whitelists where offered. According to experts, do not open ZIP or .LNK files from <a href=\"https:\/\/www.whatsapp.com\/?lang=en\" target=\"_blank\" rel=\"noopener nofollow\">WhatsApp<\/a>, even from known contacts, without verifying by a separate message or a phone call.<\/p>\n<p>Brazil At No. 5<\/p>\n<p>Chainalysis figures show Brazil sits at the top of Latin America in crypto use, and the country holds the <a href=\"https:\/\/www.chainalysis.com\/blog\/2025-global-crypto-adoption-index\/\" target=\"_blank\" rel=\"noopener nofollow\">fifth spot<\/a> in the platform\u2019s 2025 Global Crypto Adoption Index Top 20.<\/p>\n<p><em>Featured image from Gemini, chart from TradingView<\/em><\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>A new WhatsApp worm is sweeping through Brazil, stealing bank logins and crypto keys from ordinary users, security firms warn. Victims get a message that looks familiar \u2014 a delivery note, a government alert, or an invite to a group \u2014 and one click can let the threat spread through their contacts while a hidden [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"iawp_total_views":0,"footnotes":""},"categories":[2],"tags":[3,4,5],"class_list":["post-59561","post","type-post","status-publish","format-standard","hentry","category-news","tag-crypto","tag-doge","tag-news"],"_links":{"self":[{"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/posts\/59561","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=59561"}],"version-history":[{"count":0,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/posts\/59561\/revisions"}],"wp:attachment":[{"href":"https:\/\/dogewisperer.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=59561"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=59561"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=59561"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}