Brazilian Crypto Users Beware: WhatsApp Worm Threat

Cryptocurrency holders in Brazil are urged to exercise extreme caution due to a sophisticated hacking campaign involving a hijacking worm and a banking trojan being spread through WhatsApp messages. According to a new report from Trustwave’s SpiderLabs cybersecurity research team, the banking trojan, dubbed “Eternidade Stealer,” is being disseminated via social engineering tactics on WhatsApp, including “fake government programs, delivery notifications,” messages from compromised contacts, and fraudulent investment schemes.

SpiderLabs researchers Nathaniel Morales, John Basmayor, and Nikita Kazymirskyi stated, “WhatsApp remains one of the most exploited communication channels in Brazil’s cybercrime landscape. Over the past two years, malicious actors have refined their tactics, leveraging the platform's widespread popularity to distribute banking trojans and information-stealing malware.”

How the Worm and Trojan Operate

In simple terms, clicking the worm link in WhatsApp triggers a chain reaction, infecting the victim with both the worm and the banking trojan. The worm hijacks the user's account and retrieves their contact list. It then employs “smart filtering” to ignore business contacts and groups, focusing on individual contacts for a more streamlined operation.

Simultaneously, the banking trojan, a file automatically downloaded onto the victim's device, deploys the Eternidade Stealer in the background. This trojan scans for financial data and login credentials for a range of Brazilian banks, fintech companies, and cryptocurrency exchanges and wallets.

Evading Detection

The malware employs a clever method to avoid detection or takedown. Instead of relying on a fixed server address, it uses a pre-set Gmail account to check for new commands via email. This allows the hackers to alter commands by sending new emails.

“A notable feature of this malware is its use of hardcoded credentials to log into its email account, from which it fetches its C2 server. This represents a remarkably intelligent approach to updating its C2, maintaining persistence, and avoiding network-level detection or takedowns. If the malware fails to connect to the email account, it resorts to a hardcoded fallback C2 address,” the report detailed.

Staying Safe

Users of apps like WhatsApp are advised to be wary of any links sent to them, even if from a trusted contact. A useful strategy is to verify the link's legitimacy with the sender through a separate communication channel. Be especially suspicious of links sent unexpectedly with limited context.

Keeping software up-to-date can also help protect against vulnerabilities targeted by older versions, and anti-virus software can potentially flag suspicious activity.

If a user suspects their account has been compromised, it is crucial to immediately freeze all potential access points to banking and crypto services to mitigate losses. Tracking fund movements can also assist exchanges, researchers, or authorities in tracing the flow of stolen assets, potentially enabling them to freeze hacker-controlled wallets.


Risk Warning: this article represents only the author’s views and is for reference only. It does not constitute investment advice or financial guidance, nor does it represent the stance of the Markets.com platform.When considering shares, indices, forex (foreign exchange) and commodities for trading and price predictions, remember that trading CFDs involves a significant degree of risk and could result in capital loss.Past performance is not indicative of any future results. This information is provided for informative purposes only and should not be construed to be investment advice. Trading cryptocurrency CFDs and spread bets is restricted for all UK retail clients. 

Latest news

Sunday, 29 March 2026

Indices

BTC News Today: Bitcoin Recovers to $67,400 After Sharp Dip Below $65,000

Sunday, 29 March 2026

Indices

Gold price today, March 30: Gold market is currently in a corrective phase, XAU/USD rises to $4,568.50

Tuesday, 24 March 2026

Indices

NVIDIA GTC 2026 Keynote Highlights: Jensen Huang Predicts $1 Trillion AI Demand Through 2027

Tuesday, 24 March 2026

Indices

Top performing cryptos today: Siren (SIREN), Bittensor (TAO), Stellar (XLM)

Tuesday, 24 March 2026

Indices

Gold price today, March 25: Gold Surges Over $4,580 as XAUUSD Jumps 2.5% Amid Softer Dollar Pressure

Tuesday, 24 March 2026

Indices

Forex expo Dubai 2026: What is the investment event in Dubai 2026?

Monday, 23 March 2026

Indices

Commodity Market Today: Business Body Warns Middle East Conflict Could Derail SA’s 2026 Economic Recovery

Monday, 23 March 2026

Indices

Gold price today, March 24: Gold extends slide, XAU/USD price crashes below $4,200

Sunday, 22 March 2026

Indices

Gold price today, March 23: Gold drops, XAU/USD price plunges below $4,278

Sunday, 22 March 2026

Indices

BTC news today: Bitcoin keeps falling, what’s going on with bitcoin?