The post Brazilian crypto users hit by WhatsApp malware campaign targeting crypto wallets appeared on BitcoinEthereumNews.com. Bad actors are weaponizing WhatsApp to deliver a hijacking worm and banking trojan in Brazil that targets their crypto wallets. Summary SpiderLabs has warned about a WhatsApp‑based malware campaign in Brazil that deploys a worm and banking trojan to target crypto users. The malware is able to harvest sensitive information related to the victim’s crypto exchange account and wallets. Trustwave’s cybersecurity research team SpiderLabs has uncovered a major campaign involving the Eternidade Stealer, which can quietly harvest financial information, login data, and other sensitive details associated with banking portals, fintech apps, and crypto exchanges on the victim’s device. Threat actors were found to be using complex social engineering schemes involving “fake government programs, delivery notifications, and even fraudulent investment groups shared through WhatsApp messages and groups,” the report said. Attackers are using a two‑stage process to deliver the malicious payload that includes a WhatsApp‑propagating worm and a Delphi‑based banking trojan. When the victim clicks a worm link, it triggers an automated sequence that hijacks the WhatsApp session, downloads the MSI installer in the background, and deploys the stealer that scans for financial applications and crypto wallets. “When it detects a match, for example, a window title or process name linked to Bradesco, BTG Pactual, Binance, Coinbase, MetaMask, Trust Wallet, or another financial brand, the malware immediately decrypts and activates its next-stage payload,” Spiderlabs researchers explained. Another concerning trait of the campaign, besides its stealthy nature, is that the worm is able to access the victim’s contact list, which lets it target other potential victims. Meanwhile, it prevents detection by using “hardcoded credentials to log into its email account,” which is retrieved from a Gmail inbox controlled by the operator. By using IMAP over SSL to fetch commands, a method that blends with ordinary user email traffic, the malware is able… The post Brazilian crypto users hit by WhatsApp malware campaign targeting crypto wallets appeared on BitcoinEthereumNews.com. Bad actors are weaponizing WhatsApp to deliver a hijacking worm and banking trojan in Brazil that targets their crypto wallets. Summary SpiderLabs has warned about a WhatsApp‑based malware campaign in Brazil that deploys a worm and banking trojan to target crypto users. The malware is able to harvest sensitive information related to the victim’s crypto exchange account and wallets. Trustwave’s cybersecurity research team SpiderLabs has uncovered a major campaign involving the Eternidade Stealer, which can quietly harvest financial information, login data, and other sensitive details associated with banking portals, fintech apps, and crypto exchanges on the victim’s device. Threat actors were found to be using complex social engineering schemes involving “fake government programs, delivery notifications, and even fraudulent investment groups shared through WhatsApp messages and groups,” the report said. Attackers are using a two‑stage process to deliver the malicious payload that includes a WhatsApp‑propagating worm and a Delphi‑based banking trojan. When the victim clicks a worm link, it triggers an automated sequence that hijacks the WhatsApp session, downloads the MSI installer in the background, and deploys the stealer that scans for financial applications and crypto wallets. “When it detects a match, for example, a window title or process name linked to Bradesco, BTG Pactual, Binance, Coinbase, MetaMask, Trust Wallet, or another financial brand, the malware immediately decrypts and activates its next-stage payload,” Spiderlabs researchers explained. Another concerning trait of the campaign, besides its stealthy nature, is that the worm is able to access the victim’s contact list, which lets it target other potential victims. Meanwhile, it prevents detection by using “hardcoded credentials to log into its email account,” which is retrieved from a Gmail inbox controlled by the operator. By using IMAP over SSL to fetch commands, a method that blends with ordinary user email traffic, the malware is able…

Brazilian crypto users hit by WhatsApp malware campaign targeting crypto wallets

Bad actors are weaponizing WhatsApp to deliver a hijacking worm and banking trojan in Brazil that targets their crypto wallets.

Summary

  • SpiderLabs has warned about a WhatsApp‑based malware campaign in Brazil that deploys a worm and banking trojan to target crypto users.
  • The malware is able to harvest sensitive information related to the victim’s crypto exchange account and wallets.

Trustwave’s cybersecurity research team SpiderLabs has uncovered a major campaign involving the Eternidade Stealer, which can quietly harvest financial information, login data, and other sensitive details associated with banking portals, fintech apps, and crypto exchanges on the victim’s device.

Threat actors were found to be using complex social engineering schemes involving “fake government programs, delivery notifications, and even fraudulent investment groups shared through WhatsApp messages and groups,” the report said.

Attackers are using a two‑stage process to deliver the malicious payload that includes a WhatsApp‑propagating worm and a Delphi‑based banking trojan. When the victim clicks a worm link, it triggers an automated sequence that hijacks the WhatsApp session, downloads the MSI installer in the background, and deploys the stealer that scans for financial applications and crypto wallets.

“When it detects a match, for example, a window title or process name linked to Bradesco, BTG Pactual, Binance, Coinbase, MetaMask, Trust Wallet, or another financial brand, the malware immediately decrypts and activates its next-stage payload,” Spiderlabs researchers explained.

Another concerning trait of the campaign, besides its stealthy nature, is that the worm is able to access the victim’s contact list, which lets it target other potential victims.

Meanwhile, it prevents detection by using “hardcoded credentials to log into its email account,” which is retrieved from a Gmail inbox controlled by the operator. By using IMAP over SSL to fetch commands, a method that blends with ordinary user email traffic, the malware is able to bypass network filters and remain difficult to trace.

“It is a very clever way to update its C2, maintain persistence, and evade detections or takedowns on a network level. If the malware cannot connect to the email account, it uses a hardcoded fallback C2 address,” researchers added.

SpiderLabs researchers have urged Brazilian crypto users to remain alert, especially on WhatsApp, which has become a favored tool for social engineering-based malware campaigns.

“WhatsApp continues to be one of the most exploited communication channels in Brazil’s cybercrime ecosystem. Over the past two years, threat actors have refined their tactics, using the platform’s immense popularity to distribute banker trojans and information-stealing malware,” researchers warned.

Crypto adoption in Brazil has soared over the past few years, and with recent developments like potential plans to establish a national Bitcoin reserve and enforce a proper regulatory framework, the country has drawn increased attention from global investors and local users alike. On the Chainalysis Global Crypto Adoption Index, Brazil ranks fifth, while it stands as Latin America’s largest crypto market by volume.

As such, it remains a prime target for scammers and other bad actors seeking to exploit inexperienced users or take advantage of poorly protected systems.

Eternidade Stealer is a kind of infostealer, which, as mentioned above, can silently monitor applications, extract sensitive credentials, and activate fake overlays to harvest user data..

Back in September, security platform Mosyle uncovered one such cross-platform threat called ModStealer that remained undetected for weeks and was found to be targeting crypto wallets across macOS, Windows, and Linux environments. By using obfuscated JavaScript code within a Node.js environment, the malware was able to infiltrate developer systems and exfiltrate private keys and clipboard data from over 50 browser wallet extensions.

More recently, a Google Threat Intelligence Group report warned that bad actors have started using artificial intelligence to develop malware that can rewrite its own code in real time, making it a lot harder to detect or neutralize.

Source: https://crypto.news/brazilian-crypto-users-hit-by-whatsapp-malware-campaign-targeting-crypto-wallets/

Market Opportunity
Bad Idea AI Logo
Bad Idea AI Price(BAD)
$0.00000000144
$0.00000000144$0.00000000144
+1.40%
USD
Bad Idea AI (BAD) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

China Bans Nvidia’s RTX Pro 6000D Chip Amid AI Hardware Push

China Bans Nvidia’s RTX Pro 6000D Chip Amid AI Hardware Push

TLDR China instructs major firms to cancel orders for Nvidia’s RTX Pro 6000D chip. Nvidia shares drop 1.5% after China’s ban on key AI hardware. China accelerates development of domestic AI chips, reducing U.S. tech reliance. Crypto and AI sectors may seek alternatives due to limited Nvidia access in China. China has taken a bold [...] The post China Bans Nvidia’s RTX Pro 6000D Chip Amid AI Hardware Push appeared first on CoinCentral.
Share
Coincentral2025/09/18 01:09
How To Earn Crypto Cashback With Cold Wallet’s Every Transaction

How To Earn Crypto Cashback With Cold Wallet’s Every Transaction

The post How To Earn Crypto Cashback With Cold Wallet’s Every Transaction appeared on BitcoinEthereumNews.com. Crypto has long promised opportunity, but for most users, participation feels more like a penalty than a reward. Every swap, bridge, or simple transaction comes with fees that chip away at your balance. For newcomers, this becomes a barrier to entry, and for long-time users, it creates fatigue. Cold Wallet changes that equation by giving something back every time you act on-chain. Instead of paying fees into a void, you get rewarded with $CWT tokens that build your balance over time.  With over $7.11 million already raised in its presale, currently at stage 18 and priced at $0.01058 per token, Cold Wallet is proving that a fairer system isn’t just possible, it’s already here. At launch, $CWT is projected to list at $0.3517, adding even more incentive for early adopters to get involved now.  Cashback Built Into Every Action Cold Wallet introduces a simple but powerful concept: use the blockchain as usual, and you get cashback for it. Whether you’re paying gas fees, swapping between tokens, or bridging funds across networks, the wallet automatically rewards you with $CWT. There’s no staking contract to manage, no forms to fill out, and no hidden lock-ups to trap your funds. The system works in real time, making the experience seamless and effortless.  Cashback rates are tied to your tier, and with higher holdings of $CWT, you can reclaim even more of your transaction costs, up to 100% of gas fees at the top tier. For everyday users, this means turning unavoidable expenses into an income stream. For power users, it transforms frequent activity into a compounding advantage, giving them a reason to engage more often without the usual frustration of draining fees. The Role of $CWT in the Ecosystem At the heart of Cold Wallet’s cashback model is the $CWT token. Far from…
Share
BitcoinEthereumNews2025/09/26 21:27
Scott Bessent says yuan drop against euro is Europe’s problem, not America’s

Scott Bessent says yuan drop against euro is Europe’s problem, not America’s

The post Scott Bessent says yuan drop against euro is Europe’s problem, not America’s appeared on BitcoinEthereumNews.com. U.S. Treasury Secretary Scott Bessent said in Madrid on Thursday that the slump in China’s currency isn’t a problem for the United States, it’s Europe that should be worried. Speaking during a joint interview with Reuters and Bloomberg, Scott made the comments after meetings with Chinese Vice Premier He Lifeng as part of the U.S.-China trade discussions, which also included talks on TikTok. He made it clear that the yuan, also known as the renminbi, has actually strengthened against the U.S. dollar this year, but collapsed to a record low against the euro. “The RMB is actually stronger this year versus the dollar. Now it’s at an all-time low versus the euro, which is a problem for the Europeans,” Scott, rejecting the idea that Beijing was trying to devalue its currency to gain an unfair edge against Washington. He said Chinese officials haven’t tried anything of the sort with the U.S. and explained the reality behind the currency’s movement: “It’s a closed currency. So they manage the level.” Yuan collapse helps Chinese exports flood europe Since January, the yuan has plunged from 7.5 per euro to over 8.4, triggering concerns across Europe. Meanwhile, against the dollar, it’s gained slightly from 7.3 to 7.1. This divergence has created a lopsided trade dynamic, because while the U.S. has seen its imports from China drop 14% due to aggressive tariffs, Europe has recorded a 6.9% increase in trade with China. So, Scott said the U.S. tariffs are doing what they were meant to do, cutting down the trade deficit. But the redirected flow of Chinese goods is now landing in European markets instead, where the yuan’s weakness is making Chinese exports even cheaper in euro terms. The weakening of the yuan is hitting Europe at a sensitive time, as the European Central Bank…
Share
BitcoinEthereumNews2025/09/19 10:16