WhatsApp Worm Targets Brazilian Crypto Users with Banking Trojan
A new WhatsApp worm is actively spreading across Brazil, delivering the Eternidade Stealer banking trojan. The malware specifically targets cryptocurrency wallets and financial services, siphoning user credentials with alarming efficiency.
Researchers from Trustwave SpiderLabs uncovered the worm's sophisticated use of IMAP for dynamic command-and-control server updates, enabling it to evade detection. The malware hijacks WhatsApp contact lists, propagating through personalized messages—a tactic that amplifies its reach exponentially.
Notably, the worm checks for Brazilian Portuguese system settings before executing, indicating deliberate targeting of local users. This development underscores the escalating threats facing crypto holders in high-adoption regions.