Maverick Malware May Hijack WhatsApp Web Accounts Targeting Brazil
Maverick malware is a sophisticated banking trojan that targets WhatsApp Web users in Brazil, hijacking accounts to steal credentials from Latin American financial institutions. It spreads via malicious ZIP archives using VBScript and PowerShell, automating browser sessions to propagate without detection. Cybersecurity firms like CyberProof, Trend Micro, Sophos, and Kaspersky have analyzed its evasion tactics and ties to older threats like Coyote.
Maverick combines obfuscated scripts to download payloads like SORVEPOTEL worm, focusing on Brazilian users via time zone and language checks.
It automates Chrome to takeover WhatsApp sessions, sending personalized malicious messages to contacts without triggering alerts.
Linked to Water Saci actor, it monitors browser tabs for banking sites and deploys phishing pages, with overlaps to Coyote malware noted by experts.
Maverick malware threatens WhatsApp users in Brazil with account hijacking and credential theft—learn how it spreads via ZIP files and evades detection. Protect your accounts now with robust security measures. (152 characters)
Maverick malware is a banking trojan that infiltrates WhatsApp Web sessions to hijack accounts and target financial credentials from Brazilian institutions. Discovered by Trend Micro and linked to the Water Saci threat actor, it uses obfuscated VBScript and PowerShell to automate browser actions and spread via malicious ZIP archives. This self-propagating threat checks system settings to ensure deployment only in targeted regions, emphasizing its precision in attacks.
The infection begins with a ZIP archive downloaded through WhatsApp Web, containing an LNK shortcut that triggers obfuscated code to execute PowerShell commands. This loader contacts an attacker-controlled server to fetch payloads like the SORVEPOTEL worm and the Maverick banking trojan . It employs classic obfuscation techniques, such as split Base64 and UTF-16LE encoding, and self-terminates if reverse-engineering tools are detected, showcasing advanced anti-analysis measures.
CyberProof’s SOC team detailed in their investigation that the malware avoids .NET binaries, opting for VBScript named Orcamento.vbs tied to SORVEPOTEL. This script launches tadeu.ps1 in memory, which automates Chrome using ChromeDriver and Selenium to seize control of the WhatsApp session. By terminating existing Chrome processes and copying the legitimate profile, it accesses cookies and tokens to bypass authentication, granting hackers immediate access without QR code scans or alerts.
Once in control, the PowerShell payload displays a fake “WhatsApp Automation v6.0” banner to mask operations. It retrieves message templates from a command-and-control (C2) server, exfiltrates contacts, and sends personalized ZIP archives to each , incorporating time-based greetings and names for realism. Trend Micro highlighted the C2’s sophistication, enabling real-time pausing, resuming, and monitoring of propagation across infected systems.
Maverick malware specifically targets Brazil by verifying time zone, language, system region, and date formats before full deployment, restricting execution to Portuguese-language systems. It scans browser tabs for hard-coded URLs of Latin American financial institutions, then fetches phishing pages from remote servers to harvest credentials. This geofencing reduces noise and maximizes impact on high-value targets, as noted in analyses by CyberProof and Trend Micro. (98 words)
To safeguard against Maverick malware, always verify unexpected file downloads on WhatsApp Web and avoid executing unknown ZIP archives or shortcuts. Enable two-factor authentication on WhatsApp, use antivirus software with real-time scanning, and keep browsers updated to block automation exploits. Regularly clear browser data and monitor for suspicious automation banners—if you spot unusual activity like automated messaging, immediately log out and scan your device for threats. (72 words)
The Maverick malware campaign underscores the growing risks to WhatsApp Web users in Brazil, leveraging obfuscated loaders and session hijacking to enable credential theft from financial institutions. As cybersecurity firms like CyberProof, Trend Micro, Sophos, and Kaspersky continue to track its evolution from threats like Coyote, users must prioritize vigilance against malicious downloads. Staying informed and adopting proactive defenses will be crucial as attackers refine these tactics for broader impact in the digital landscape.
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
Ethereum News Update: Is Ethereum Really Headed for $60k? Kiyosaki's Confident Prediction or Just a Mistake?
- Robert Kiyosaki predicts Bitcoin could hit $250,000 and Ethereum $60,000 by 2026, challenging traditional finance norms. - His strategy emphasizes Bitcoin/gold as inflation hedges, citing Gresham's Law and Metcalfe's Law to justify decentralized asset accumulation. - Market reactions are mixed: critics dismiss his long-term crash warnings, while on-chain data and Arthur Hayes support potential rebounds. - Kiyosaki's bullish stance highlights growing crypto legitimacy as value stores, despite regulatory r
Bitcoin Updates: SoFi Integrates Banking with Cryptocurrency, Providing Safe Trading via an FDIC-Insured Application
- SoFi becomes first FDIC-insured U.S. bank to launch consumer crypto trading via its app, integrating banking and digital assets under regulatory oversight. - The service enables users to trade Bitcoin , Ethereum , and Solana directly from FDIC-protected accounts, emphasizing "bank-grade" security and eliminating external fund transfers. - A 60% user preference for bank-based crypto trading and 2025 regulatory clarity from OCC support the move, aligning with doubled U.S. crypto ownership and industry tren
SEC's Token Classification Ignites Regulatory Dispute With CFTC Over Cryptocurrency Oversight
- SEC proposes token taxonomy framework to classify crypto assets, excluding decentralized tokens and utilities from securities under the 1946 Howey Test. - Bipartisan bills aim to shift crypto commodity oversight to CFTC, raising concerns over agency capacity amid staffing shortages and pending leadership confirmations. - Regulatory overlap between SEC and CFTC intensifies as Congress seeks cohesive frameworks, balancing innovation incentives with investor protections in evolving crypto markets.
IPO Genie's Airdrop Connects Individual Investors with Elite Private Market Opportunities
- IPO Genie's $50,000 airdrop drives 320% sign-up surge, rewarding 40 participants with $IPO tokens for private-market access. - AI-powered blockchain platform offers utility-focused tokens with staking/governance rights, raising $12.5M from 40+ countries. - Merkle tree verification and linear vesting enhance credibility, though phishing risks and liquidity volatility remain concerns. - Phase 5 at 95% capacity creates urgency as stricter eligibility and higher prices loom in Phase 6, per Blockchain Reporte
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
