ModStealer is a malware family tracked across 2 threat clusters and 2 intelligence report mentions on ThreatCluster. First observed November 20, 2025; most recent activity November 20, 2025.
ModStealer is a malware family implicated in a Brazil-focused campaign that weaponizes WhatsApp to target cryptocurrency users. It appears to focus on exfiltrating credentials and wallet data through social-engineering and distribution via a popular messaging platform, underscoring the growing use of mainstream apps as infection vectors in crypto-focused threats.
A sophisticated malware campaign in Brazil is exploiting WhatsApp to target cryptocurrency users, deploying a banking trojan named 'Eternidade Stealer.' This malware hijacks devices, steals financial data, and spreads…
A security flaw in WhatsApp allowed researchers to extract phone numbers of 3.5 billion users. The exploit involved systematically checking numbers through the app's discovery feature, revealing profile photos for 57%…