Brazilian Crypto Users Beware: WhatsApp Worm Threat

Cryptocurrency holders in Brazil are urged to exercise extreme caution due to a sophisticated hacking campaign involving a hijacking worm and a banking trojan being spread through WhatsApp messages. According to a new report from Trustwave’s SpiderLabs cybersecurity research team, the banking trojan, dubbed “Eternidade Stealer,” is being disseminated via social engineering tactics on WhatsApp, including “fake government programs, delivery notifications,” messages from compromised contacts, and fraudulent investment schemes.

SpiderLabs researchers Nathaniel Morales, John Basmayor, and Nikita Kazymirskyi stated, “WhatsApp remains one of the most exploited communication channels in Brazil’s cybercrime landscape. Over the past two years, malicious actors have refined their tactics, leveraging the platform's widespread popularity to distribute banking trojans and information-stealing malware.”

How the Worm and Trojan Operate

In simple terms, clicking the worm link in WhatsApp triggers a chain reaction, infecting the victim with both the worm and the banking trojan. The worm hijacks the user's account and retrieves their contact list. It then employs “smart filtering” to ignore business contacts and groups, focusing on individual contacts for a more streamlined operation.

Simultaneously, the banking trojan, a file automatically downloaded onto the victim's device, deploys the Eternidade Stealer in the background. This trojan scans for financial data and login credentials for a range of Brazilian banks, fintech companies, and cryptocurrency exchanges and wallets.

Evading Detection

The malware employs a clever method to avoid detection or takedown. Instead of relying on a fixed server address, it uses a pre-set Gmail account to check for new commands via email. This allows the hackers to alter commands by sending new emails.

“A notable feature of this malware is its use of hardcoded credentials to log into its email account, from which it fetches its C2 server. This represents a remarkably intelligent approach to updating its C2, maintaining persistence, and avoiding network-level detection or takedowns. If the malware fails to connect to the email account, it resorts to a hardcoded fallback C2 address,” the report detailed.

Staying Safe

Users of apps like WhatsApp are advised to be wary of any links sent to them, even if from a trusted contact. A useful strategy is to verify the link's legitimacy with the sender through a separate communication channel. Be especially suspicious of links sent unexpectedly with limited context.

Keeping software up-to-date can also help protect against vulnerabilities targeted by older versions, and anti-virus software can potentially flag suspicious activity.

If a user suspects their account has been compromised, it is crucial to immediately freeze all potential access points to banking and crypto services to mitigate losses. Tracking fund movements can also assist exchanges, researchers, or authorities in tracing the flow of stolen assets, potentially enabling them to freeze hacker-controlled wallets.


Risk Warning: This article is provided for informational purposes only and does not constitute investment advice, investment research, or a recommendation to trade. The views expressed are those of the author and do not necessarily reflect the position of Markets.com. When considering shares, indices, forex (foreign exchange), and commodities for trading and price predictions, remember that trading CFDs involves a significant degree of risk and may not be suitable for all investors. Leveraged products can result in capital loss. Past performance is not indicative of future results. Before trading, ensure you fully understand the risks involved and consider your investment objectives and level of experience. Cryptocurrency CFD trading restrictions may apply depending on jurisdiction.

Latest news

Thursday, 14 May 2026

Indices

Gold Price Today, May 15: XAU/USD Consolidates in $4,650–$4,690 Range Amid Fed Policy Uncertainty

Thursday, 14 May 2026

Indices

Korean Stock Market Crash: Samsung and SK Hynix Power KOSPI to Record Highs

Wednesday, 13 May 2026

Indices

NVDA News Today: Developments in NVIDIA AI Ecosystem Partnerships

Wednesday, 13 May 2026

Indices

Gold price today, May 14: XAU/USD near $4,700, gold steady ahead of Trump-Xi talks

Tuesday, 12 May 2026

Indices

Record Inflows Pour into South African Markets Amid Reform Momentum: $42 Billion Foreign Investment Surge

Tuesday, 12 May 2026

Indices

Gold Price Today, May 13: Gold Plunges Below $4,700 as Hot US CPI & Surging Oil Crush Rate-Cut Hopes

Monday, 11 May 2026

Indices

Latest ETF News Highlights: BTC Price (BTC/USD) Holds at $81,500 Amid Strong Bitcoin ETF Inflows

Monday, 11 May 2026

Indices

Gold Price Today, May 12: XAU/USD Rises Sharply After Fed Cut Live Gold Price at $4,750

Sunday, 10 May 2026

Indices

Stock Market Today: Nifty Slips Below 24,200, Sensex Drops to 77,328 as Oil Crosses $100

Sunday, 10 May 2026

Indices

Gold Price Today, May 11: Gold (XAUUSD) Trading at $4,695, Central Banks Keep Buying as Investors Seek Shelter