Particle.news
Download on the App Store

WhatsApp Malware 'Sorvepotel' Spreads in Brazil, Exploiting Web Sessions to Steal Banking Credentials

Trend Micro attributes most of 477 observed infections to Brazil, prompting new warnings.

Overview

  • The campaign starts with ZIP attachments or links that deliver Windows shortcuts and scripts, which install persistent malware on desktop machines.
  • If WhatsApp Web is active, the malware automatically forwards the malicious file to contacts and groups, driving infection chains and risking suspensions for spam-like behavior.
  • Researchers report the malware surveils browsers and can overlay fake banking and crypto logins to harvest passwords and one-time codes.
  • Telemetry shows 457 of 477 detections in Brazil, with language and locale checks indicating deliberate targeting of Brazilian users and organizations.
  • Security guidance urges disabling automatic downloads, limiting file transfers on corporate devices, keeping endpoints updated, disconnecting WhatsApp Web when idle, and verifying unexpected attachments, while WhatsApp issued a general safety statement.