Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

This Week in Crypto Law (May 30, 2026)

June 9, 2026

FTX Token’s 20% rally raises trend reversal hopes – But can FTT confirm?

June 9, 2026

Slide.fun Joins Forces With SportixAI To Power Web3 Gamification With Actionable On-Chain Insights

June 9, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»Eternidade Stealer Trojan Fuels Aggressive Brazil Cybercrime
Eternidade Stealer Trojan Fuels Aggressive Brazil Cybercrime
Security and Privacy

Eternidade Stealer Trojan Fuels Aggressive Brazil Cybercrime

November 19, 2025No Comments2 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

A newly identified banking Trojan known as Eternidade Stealer has been observed pushing Brazil’s cybercrime ecosystem into a more aggressive phase, with attackers using WhatsApp as both an entry point and a propagation tool.

According to new research from Trustwave SpiderLabs, the malware combines a WhatsApp-propagating worm, a Delphi-based stealer and an MSI dropper to harvest financial data, system details and contact lists used for rapid lateral spread.

The researchers noted that a shift to Python for WhatsApp hijacking, along with dynamic command-and-control (C2) retrieval through IMAP, marks a notable evolution in the threat actor’s toolkit.

A Two-Payload Campaign

The campaign relies on an obfuscated VBScript that downloads two payloads: a Python-written WhatsApp worm and an installer that deploys a Delphi-built banking Trojan.

Shorter, more agile scripting enables attackers to automate WhatsApp messaging, extract contact lists using wppconnect libraries and push malicious files to victims. Messages adapt their greeting based on the time of day and insert the recipient’s name.

The Eternidade Stealer component activates only on systems using Brazilian Portuguese and scans for banking, fintech and cryptocurrency applications before triggering credential-harvesting overlays. The malware also stores hard-coded email credentials that allow it to pull fresh C2 details from an IMAP mailbox for extra resilience against takedowns.

Read more on WhatsApp-based malware campaigns: NSO Group Hit with $168m Fine for WhatsApp Pegasus Spyware Abuse

How the Malware Operates

The dropper installs several components, including AutoIt-based scripts that perform reconnaissance, detect antivirus tools, gather system telemetry and decrypt embedded payloads.

Once active, the stealer checks for prior infection, collects host information and browser window details and targets applications from banks such as Itaú, Santander, Bradesco and Caixa, along with services like MercadoPago and Binance, among others.

See also  South Africa’s Aggressive New Capital Flow Rules

Key capabilities include:

  • Dynamic C2 discovery using IMAP

  • WhatsApp contact theft and automated message distribution

  • Banking overlays for credential interception

  • Process hollowing via Delphi injectors

  • System profiling and AV detection

Broader Infrastructure Findings

The Trustwave SpiderLabs team traced the campaign’s backend to several related domains and panels used for redirect management and victim tracking.

Logs showed 454 connection attempts from 38 countries, with only a handful originating in Brazil, despite the malware’s regional focus.

Most visitors used desktop systems, suggesting that the campaign was designed for workstation environments rather than mobile endpoints.

“Cybersecurity defenders should remain vigilant for suspicious WhatsApp activity, unexpected MSI or script executions and indicators linked to this ongoing campaign,” the researchers concluded.

Source link

Aggressive Brazil Cybercrime Eternidade Fuels Stealer Trojan
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

North Korean Hackers Use Fake Coding Tasks to Steal Crypto

June 8, 2026

Tether-backed Adecoagro launches 10 MW sugarcane-powered Bitcoin mining pilot in Brazil

June 3, 2026

Infosecurity Europe: AI-Powered Cybercrime Tools Surge on Dark Web

June 3, 2026

Stake DAO Freezes Arbitrum vsdCRV Markets After Attacker Mints 5.4T Synthetic Tokens

May 29, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Environmentalists Rally Against Crypto Mining Facility Renewal in New York, Citing Climate Concerns

September 11, 2023

Taki Games Merges with Unite and Partners with Quickswap

January 19, 2024

US exodus drives crypto ETP outflows to record $6.4B but XRP defies downturn

March 17, 2025

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

This Week in Crypto Law (May 30, 2026)

June 9, 2026

FTX Token’s 20% rally raises trend reversal hopes – But can FTT confirm?

June 9, 2026

Slide.fun Joins Forces With SportixAI To Power Web3 Gamification With Actionable On-Chain Insights

June 9, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$60,885.00-4.30%
  • ethereumEthereum(ETH)$1,618.37-4.33%
  • tetherTether(USDT)$1.00-0.03%
  • binancecoinBNB(BNB)$585.15-3.24%
  • usd-coinUSDC(USDC)$1.000.00%
  • rippleXRP(XRP)$1.12-3.69%
  • solanaSolana(SOL)$63.81-4.93%
  • tronTRON(TRX)$0.321451-1.39%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.03-0.52%
  • HyperliquidHyperliquid(HYPE)$59.06-7.90%