Bitcoin Forum
December 05, 2025, 12:43:19 AM *
News: Latest Bitcoin Core release: 30.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Water Saci - AI enhanced malware targeting Brazilians thru WhatApp  (Read 24 times)
fullfitlarry (OP)
Full Member
***
Offline Offline

Activity: 196
Merit: 121


You Attract What You Are


View Profile
December 04, 2025, 09:07:37 AM
 #1

Water Saci has evolved it's tactics, now it's uses a very highly layered infection chain. And it uses WhatApp to propagate a banking trojan that target Brazil again. Not just banking apps, but it also in it's cross hair, crypto exchanges and wallet.



The thing is that this cyber actors are using AI to convert their code,

Quote
propagation scripts from PowerShell to Python exemplifies a layered approach that has enabled Water Saci to bypass conventional security controls, exploit user trust across multiple channels, and ramp up their infection rates.

I have nothing against AI, but this could be one of it's pitfall.

https://www.trendmicro.com/en_us/research/25/l/water-saci.html

The attack starts from WhatsApp, receiving a compressed archived files such as ZIP files, while other mode of attack showed to be a PDF documents, looks very harmless as first because it just shows to update your Adobe Reader.

But that is not the case as it has payload and once you installed, it's game over.



So again, just a friendly reminder for our Brazilian community, as this is not the first time that they have been targeted thru WhatApp, you can read it here, Eternidade Stealer - targets Banking apps/Crypto Wallets/Exhanges.

joniboini
Legendary
*
Offline Offline

Activity: 2758
Merit: 1858



View Profile WWW
December 04, 2025, 02:56:28 PM
 #2

Another malware using WhatsApp, no surprise there. Not familiar with the name, but won't be surprised if another attacker uses a similar method to attack the user base in another country.

I'm not sure about using AI to evolve the code, though. Judging from how broken some popular services are after they pivot to AI, I don't think they're that robust. I guess you could say they use a modified LLM trained with antimalware codes, so it's more specialized. Nothing's wrong with being careful.

.
 betpanda.io 
 
ANONYMOUS & INSTANT
.......ONLINE CASINO.......
▄███████████████████████▄
█████████████████████████
█████████████████████████
████████▀▀▀▀▀▀███████████
████▀▀▀█░▀▀░░░░░░▄███████
████░▄▄█▄▄▀█▄░░░█▄░▄█████
████▀██▀░▄█▀░░░█▀░░██████
██████░░▄▀░░░░▐░░░▐█▄████
██████▄▄█░▀▀░░░█▄▄▄██████
█████████████████████████
█████████████████████████
█████████████████████████
▀███████████████████████▀
▄███████████████████████▄
█████████████████████████
██████████▀░░░▀██████████
█████████░░░░░░░█████████
███████░░░░░░░░░███████
████████░░░░░░░░░████████
█████████▄░░░░░▄█████████
███████▀▀▀█▄▄▄█▀▀▀███████
██████░░░░▄░▄░▄░░░░██████
██████░░░░█▀█▀█░░░░██████
██████░░░░░░░░░░░░░██████
█████████████████████████
▀███████████████████████▀
▄███████████████████████▄
█████████████████████████
██████████▀▀▀▀▀▀█████████
███████▀▀░░░░░░░░░███████
██████░░░░░░░░░░░░▀█████
██████░░░░░░░░░░░░░░▀████
██████▄░░░░░░▄▄░░░░░░████
████▀▀▀▀▀░░░█░░█░░░░░████
████░▀░▀░░░░░▀▀░░░░░█████
████░▀░▀▄░░░░░░▄▄▄▄██████
█████░▀░█████████████████
█████████████████████████
▀███████████████████████▀
.
SLOT GAMES
....SPORTS....
LIVE CASINO
▄░░▄█▄░░▄
▀█▀░▄▀▄░▀█▀
▄▄▄▄▄▄▄▄▄▄▄   
█████████████
█░░░░░░░░░░░█
█████████████

▄▀▄██▀▄▄▄▄▄███▄▀▄
▄▀▄█████▄██▄▀▄
▄▀▄▐▐▌▐▐▌▄▀▄
▄▀▄█▀██▀█▄▀▄
▄▀▄█████▀▄████▄▀▄
▀▄▀▄▀█████▀▄▀▄▀
▀▀▀▄█▀█▄▀▄▀▀

Regional Sponsor of the
Argentina National Team
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!