WhatsApp Worm Spreads Banking Trojan Across Brazil, Targets Crypto Wallets
A sophisticated malware campaign leveraging WhatsApp has emerged in Brazil, deploying the Eternidade Stealer banking trojan to compromise crypto wallets and financial logins. The attack, first identified by Trustwave SpiderLabs in November 2025, exploits social engineering tactics—posing as government programs, delivery notifications, and investment opportunities—to lure victims into clicking malicious links.
The worm component hijacks WhatsApp accounts, selectively targeting individual contacts with personalized messages in Portuguese. Meanwhile, the trojan silently infiltrates devices, scanning for and exfiltrating credentials from financial apps and crypto exchanges. Latin America's largest digital asset market faces heightened risks as the malware's smart filtering avoids business contacts to maximize success rates.