Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnSquareMore
Brazilian crypto users hit by WhatsApp malware campaign targeting crypto walletsBad actors get creative with crypto targeting malware

Brazilian crypto users hit by WhatsApp malware campaign targeting crypto walletsBad actors get creative with crypto targeting malware

Crypto.NewsCrypto.News2025/11/19 16:00
By:By Rony RoyEdited by Dorian Batycka

Bad actors are weaponizing WhatsApp to deliver a hijacking worm and banking trojan in Brazil that targets their crypto wallets.

Summary
  • SpiderLabs has warned about a WhatsApp‑based malware campaign in Brazil that deploys a worm and banking trojan to target crypto users.
  • The malware is able to harvest sensitive information related to the victim’s crypto exchange account and wallets.

Trustwave’s cybersecurity research team SpiderLabs has uncovered a major campaign involving the Eternidade Stealer, which can quietly harvest financial information, login data, and other sensitive details associated with banking portals, fintech apps, and crypto exchanges on the victim’s device.

Threat actors were found to be using complex social engineering schemes involving “fake government programs, delivery notifications, and even fraudulent investment groups shared through WhatsApp messages and groups,” the report said.

Attackers are using a two‑stage process to deliver the malicious payload that includes a WhatsApp‑propagating worm and a Delphi‑based banking trojan. When the victim clicks a worm link, it triggers an automated sequence that hijacks the WhatsApp session, downloads the MSI installer in the background, and deploys the stealer that scans for financial applications and crypto wallets .

“When it detects a match, for example, a window title or process name linked to Bradesco, BTG Pactual, Binance, Coinbase, MetaMask, Trust Wallet, or another financial brand, the malware immediately decrypts and activates its next-stage payload,” Spiderlabs researchers explained.

Another concerning trait of the campaign, besides its stealthy nature, is that the worm is able to access the victim’s contact list, which lets it target other potential victims.

Meanwhile, it prevents detection by using “hardcoded credentials to log into its email account,” which is retrieved from a Gmail inbox controlled by the operator. By using IMAP over SSL to fetch commands, a method that blends with ordinary user email traffic, the malware is able to bypass network filters and remain difficult to trace.

“It is a very clever way to update its C2, maintain persistence, and evade detections or takedowns on a network level. If the malware cannot connect to the email account, it uses a hardcoded fallback C2 address,” researchers added.

SpiderLabs researchers have urged Brazilian crypto users to remain alert, especially on WhatsApp, which has become a favored tool for social engineering-based malware campaigns.

“WhatsApp continues to be one of the most exploited communication channels in Brazil’s cybercrime ecosystem. Over the past two years, threat actors have refined their tactics, using the platform’s immense popularity to distribute banker trojans and information-stealing malware,” researchers warned.

Crypto adoption in Brazil has soared over the past few years, and with recent developments like potential plans to establish a national Bitcoin reserve and enforce a proper regulatory framework, the country has drawn increased attention from global investors and local users alike. On the Chainalysis Global Crypto Adoption Index , Brazil ranks fifth, while it stands as Latin America’s largest crypto market by volume.

As such, it remains a prime target for scammers and other bad actors seeking to exploit inexperienced users or take advantage of poorly protected systems.

Bad actors get creative with crypto targeting malware

Eternidade Stealer is a kind of infostealer, which, as mentioned above, can silently monitor applications, extract sensitive credentials, and activate fake overlays to harvest user data..

Back in September, security platform Mosyle uncovered one such cross-platform threat called ModStealer that remained undetected for weeks and was found to be targeting crypto wallets across macOS, Windows, and Linux environments. By using obfuscated JavaScript code within a Node.js environment, the malware was able to infiltrate developer systems and exfiltrate private keys and clipboard data from over 50 browser wallet extensions.

More recently, a Google Threat Intelligence Group report warned that bad actors have started using artificial intelligence to develop malware that can rewrite its own code in real time, making it a lot harder to detect or neutralize.

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

Crypto Market Fluctuations Increase Interest in Stable Cloud Mining Solutions

- 2025 crypto market volatility drives demand for cloud mining platforms like WPAHash, offering guaranteed returns amid price swings. - WPAHash's tiered contracts with $15+ hashrate rewards and automated crypto deposits attract XRP/ETH investors seeking passive income. - ACME Solar and Aslan Energy integrate renewables with mining, signaling decarbonization trends in energy-intensive crypto operations. - Market fragmentation persists as platforms like BlockHaven focus on trading, while ETFs and mobile app

Bitget-RWA2025/11/24 17:40
Crypto Market Fluctuations Increase Interest in Stable Cloud Mining Solutions

Dogecoin Latest Updates: DOGE Rises Sharply After Initiative Fails—Is the Market Acting Irrationally?

- ZKP's Initial Coin Auction (ICA) releases 200M tokens daily via ETH/USDC bids, partnering with FC Barcelona to redefine token distribution. - Dogecoin (DOGE) surges 2.6% despite Musk-led DOGE agency's dissolution, with Grayscale ETFs boosting institutional altcoin exposure. - DOGE's price rally defies agency closure, driven by TD Sequential indicator signals and $58M debut for XRP ETF , though long-term impact remains uncertain. - Memecoin Memecore (M) struggles with sideways trading at $2.105, facing be

Bitget-RWA2025/11/24 17:40
Dogecoin Latest Updates: DOGE Rises Sharply After Initiative Fails—Is the Market Acting Irrationally?

Internet Computer in 2025: Hype-Driven Speculation or Genuine Technological Leap?

- Internet Computer (ICP) surged 30–39% in November 2025 amid market volatility, sparking debates over speculative vs. fundamental drivers. - Speculative signs include 100% weekly price swings, rising TVL ($237B) from institutional flows, and declining DApp engagement (-22.4%). - Fundamental gains include decentralized AI advancements, Microsoft/Google partnerships, and industrial IoT integrations boosting enterprise appeal. - Risks persist: SEC scrutiny, Solana/Ethereum competition, and TVL-DApp divergenc

Bitget-RWA2025/11/24 17:40
Internet Computer in 2025: Hype-Driven Speculation or Genuine Technological Leap?

ICP Price Jumps 30%: What’s Fueling This Meme-Stock-Like Surge in Web3?

- ICP token surged 30% in Nov 2025, mirroring meme-stock volatility amid Web3 speculation. - NEXPACE's $50M Ecosystem Fund for MapleStory Universe drove rally, promoting blockchain-gaming integration and RWA/AI infrastructure. - Retail FOMO amplified by social media narratives, despite ICP lacking institutional sell-side analysis unlike WeShop (WSHP). - Long-term viability remains uncertain due to limited adoption metrics, with price volatility tied to speculative momentum over proven fundamentals.

Bitget-RWA2025/11/24 17:40
ICP Price Jumps 30%: What’s Fueling This Meme-Stock-Like Surge in Web3?