PANews|Nov 20, 2025 04:06
[Crypto-Stealing Worm Attack Spreading via WhatsApp in Brazil]
According to Cointelegraph, hackers in Brazil are spreading a combination of 'worm + banking Trojan' through WhatsApp, delivering the 'Eternidade Stealer' to steal cryptocurrency wallets and financial account login information. The worm hijacks accounts and intelligently filters groups and business contacts, spreading only to personal contacts. The Trojan automatically downloads and executes, scanning local financial data as well as login credentials for multiple banks, exchanges, and wallets. This malware uses a pre-configured Gmail account to receive and update C2 commands, and falls back to hardcoded C2 servers to maintain persistence and evade takedowns when unable to connect. Security team SpiderLabs advises caution when clicking on unfamiliar or unexpected links and recommends immediately freezing access to banking and crypto services if compromised.
Share To
Timeline
HotFlash
APP
X
Telegram
CopyLink