How a Python-Based WhatsApp Worm is Targeting Brazilian Crypto And Fintech Wallets

How a Python-Based WhatsApp Worm is Targeting Brazilian Crypto And Fintech Wallets

A fast-spreading WhatsApp worm written in Python is rapidly compromising devices across Brazil, hijacking user accounts and deploying a highly capable banking trojan known as Eternidade Stealer. The campaign, uncovered by Brazilian cybersecurity researchers, highlights how messaging platforms are becoming high-impact delivery systems for credential theft and crypto fraud.

The worm leverages WhatsApp Web to propagate, uses clever command-and-control techniques through Gmail inbox monitoring, and specifically targets financial data from Brazilian banking, fintech, and crypto services. Because of its regional focus, the malware automatically self-destructs if the user’s operating system language is not set to Brazilian Portuguese.

What makes this WhatsApp worm different from typical malware?

The worm distinguishes itself through its hybrid architecture: a Python-based propagation mechanism paired with a Delphi-coded banking stealer.

The worm is delivered through deceptive WhatsApp messages—often impersonating government programs, delivery alerts, investment groups, or known contacts. When the user opens the malicious file or link, the worm activates and begins managing the victim’s WhatsApp session through WhatsApp Web.

It does two things simultaneously:

  1. Installs the Eternidade Stealer banking trojan
  2. Self-spreads by sending the same malicious payload to the victim’s WhatsApp contacts and group chats

This dual behavior allows the malware to grow exponentially while quietly harvesting sensitive financial information in the background.

How the Eternidade Stealer steals banking and crypto credentials

Once deployed, the Delphi-based trojan initiates a full scan of the device, looking for:

The Trojan is capable of:

Eternidade Stealer is designed to target the most widely used financial services in Brazil. This is why the worm first checks the OS language setting. If the system isn’t configured to Brazilian Portuguese, it ends its execution to avoid drawing international attention or triggering broader cybersecurity investigations.

How the command-and-control system works through Gmail

One of the most unconventional aspects of the campaign is its use of Gmail as a command relay mechanism.

The worm comes with hardcoded login details for a Gmail account. It checks the subject or body of the most recent email in the inbox to retrieve the active command-and-control (C2) address. This method offers multiple advantages:

If Gmail access fails, the worm turns to a hardcoded fallback C2 address. This redundancy ensures the malware remains operational even if its primary control channel is disrupted.

How the worm spreads through WhatsApp Web

WhatsApp’s widespread usage in Brazil makes it an ideal propagation vector.

After compromising a device, the worm:

The attacker does not need direct access to the phone. As long as the victim has an active WhatsApp Web session logged in on their computer, the worm can automate message sending silently.

This “social trust piggybacking” dramatically increases infection rates because recipients assume the links are legitimate.

Why Brazil is facing repeated WhatsApp-targeted attacks

Brazil has become one of the most active targets for WhatsApp-delivered malware for several reasons:

In September, another WhatsApp-propagating worm named Water Saci (also known as SORVEPOTEL) was discovered. That worm acted as a launcher for .NET-based banking trojans Maverick and Coyote, targeting both Brazil and parts of Argentina. The campaign is reportedly still ongoing.

The recurring pattern shows a shift in how financial malware operates across the region, with messaging apps now functioning as primary attack vectors instead of email or drive-by downloads.

Why this attack matters for consumers and financial institutions

A direct threat to Brazil’s digital payment ecosystem

Because Brazilian consumers rely heavily on instant payment platforms like PIX, malware capable of capturing financial credentials poses a severe risk.

Increased exposure for crypto traders

With crypto adoption rising rapidly in Brazil, theft of wallet keys or exchange logins can lead to irreversible losses.

A challenge for fintech companies

Fintech apps operating in Brazil face increased pressure to implement deeper behavioral monitoring, stronger device fingerprinting, and real-time fraud detection.

Escalating sophistication of cybercriminal groups

The combined use of WhatsApp propagation, Gmail-based C2 updates, and geo-targeting shows a level of strategic planning that suggests well-organized cybercrime operations.

How users can protect themselves from WhatsApp-based malware

While the article focuses on the incident, some practical steps should be highlighted for readers:

TL;DR

Exit mobile version