Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

CMC Releases Analysis and Guidance for Education Sector After Canvas D

June 26, 2026

DragonForce Hackers Abuse Microsoft Teams Relays to Hide Backdoor.Turn C2 Traffic

June 26, 2026

macOS Flaw Lets Standard Users Disable EDR and MDM

June 26, 2026
Facebook X (Twitter) Instagram
Friday, June 26
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Eternidade Stealer Trojan Fuels Aggressive Brazil Cybercrime
News

Eternidade Stealer Trojan Fuels Aggressive Brazil Cybercrime

Team-CWDBy Team-CWDNovember 20, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


A newly identified banking Trojan known as Eternidade Stealer has been observed pushing Brazil’s cybercrime ecosystem into a more aggressive phase, with attackers using WhatsApp as both an entry point and a propagation tool.

According to new research from Trustwave SpiderLabs, the malware combines a WhatsApp-propagating worm, a Delphi-based stealer and an MSI dropper to harvest financial data, system details and contact lists used for rapid lateral spread.

The researchers noted that a shift to Python for WhatsApp hijacking, along with dynamic command-and-control (C2) retrieval through IMAP, marks a notable evolution in the threat actor’s toolkit.

A Two-Payload Campaign

The campaign relies on an obfuscated VBScript that downloads two payloads: a Python-written WhatsApp worm and an installer that deploys a Delphi-built banking Trojan.

Shorter, more agile scripting enables attackers to automate WhatsApp messaging, extract contact lists using wppconnect libraries and push malicious files to victims. Messages adapt their greeting based on the time of day and insert the recipient’s name.

The Eternidade Stealer component activates only on systems using Brazilian Portuguese and scans for banking, fintech and cryptocurrency applications before triggering credential-harvesting overlays. The malware also stores hard-coded email credentials that allow it to pull fresh C2 details from an IMAP mailbox for extra resilience against takedowns.

Read more on WhatsApp-based malware campaigns: NSO Group Hit with $168m Fine for WhatsApp Pegasus Spyware Abuse

How the Malware Operates

The dropper installs several components, including AutoIt-based scripts that perform reconnaissance, detect antivirus tools, gather system telemetry and decrypt embedded payloads.

Once active, the stealer checks for prior infection, collects host information and browser window details and targets applications from banks such as Itaú, Santander, Bradesco and Caixa, along with services like MercadoPago and Binance, among others.

Key capabilities include:

  • Dynamic C2 discovery using IMAP

  • WhatsApp contact theft and automated message distribution

  • Banking overlays for credential interception

  • Process hollowing via Delphi injectors

  • System profiling and AV detection

Broader Infrastructure Findings

The Trustwave SpiderLabs team traced the campaign’s backend to several related domains and panels used for redirect management and victim tracking.

Logs showed 454 connection attempts from 38 countries, with only a handful originating in Brazil, despite the malware’s regional focus.

Most visitors used desktop systems, suggesting that the campaign was designed for workstation environments rather than mobile endpoints.

“Cybersecurity defenders should remain vigilant for suspicious WhatsApp activity, unexpected MSI or script executions and indicators linked to this ongoing campaign,” the researchers concluded.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleAndroid Trojan ‘Fantasy Hub’ Malware Service Turns Telegram Into a Hub for Hackers
Next Article Npm Package Targeting GitHub-Owned Repositories Flagged as Red Team Exercise
Team-CWD
  • Website

Related Posts

News

CMC Releases Analysis and Guidance for Education Sector After Canvas D

June 26, 2026
News

DragonForce Hackers Abuse Microsoft Teams Relays to Hide Backdoor.Turn C2 Traffic

June 26, 2026
News

macOS Flaw Lets Standard Users Disable EDR and MDM

June 26, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

How to mitigate the security and privacy risks of smart glasses

May 11, 2026

A quick guide to recovering a hacked account

March 21, 2026

Look out for phony verification pages spreading malware

September 14, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.