Listen to this Post

Introduction
Brazil’s cybercrime landscape is entering one of its most aggressive chapters as a new malware strain called Eternidade Stealer tears through WhatsApp networks. The threat blends social engineering with technical sophistication, turning WhatsApp into both a weapon and a delivery channel. This new wave of attacks bypasses traditional defenses, steals banking credentials, spreads through automated chats and dynamically shifts its infrastructure to stay alive. Researchers warn that the combination of Python based hijacking, IMAP driven command retrieval and a Delphi core stealer represents a dangerous leap forward for Brazil’s digital underground. This investigation breaks down how the campaign works, why it is so effective and what it signals about the future of regional cybercrime.
Main Summary
Brazil’s Cybercrime Scene Faces a New Evolution
Trustwave SpiderLabs uncovered a sophisticated malware campaign built around a banking Trojan known as Eternidade Stealer. This threat marks a sharp escalation in Brazil’s malware ecosystem because it merges worm like propagation through WhatsApp with a powerful financial data stealer hidden inside a multi stage dropper.
WhatsApp Becomes Both Entry Point and Multiplication Tool
The malware abuses WhatsApp not just as a platform for initial infection but as a core propagation engine. Attackers leverage automated scripts capable of sending personalized malicious messages that include time based greetings and victim names. This personal touch gives the campaign an unusually high infection success rate.
Dual Payload Engineering Increases Efficiency
The infection begins with a heavily obfuscated VBScript that fetches two payloads. The first is a Python built WhatsApp worm capable of hijacking sessions, gathering contacts and sending self spreading messages. The second payload is an installer that deploys the Delphi based Eternidade Stealer. The combination allows attackers to spread quickly while simultaneously setting up long term data theft capabilities.
Python Based WhatsApp Hijacking Marks a Technical Shift
Researchers highlighted a shift to Python for hijacking WhatsApp sessions, taking advantage of libraries like wppconnect to automate chat interactions at scale. This lets attackers scrape contacts instantly and distribute infected files without requiring manual input. Automation is the heart of this campaign and explains its rapid spread.
Regional Targeting Through Language Detection
Eternidade Stealer activates only on systems configured with Brazilian Portuguese. This ensures that the Trojan focuses on the country’s financial infrastructure and avoids unnecessary exposure that could attract international law enforcement. Once active, it scans for banking, fintech, cryptocurrency and e commerce applications used widely in Brazil.
Targeted Banks and Apps Under Attack
The Trojan includes overlays and credential harvesting functions aimed at prominent institutions such as Itaú, Bradesco, Santander, Caixa and services like MercadoPago and Binance. When victims open these apps, the malware injects fake windows to intercept login data.
Dynamic Command and Control Through Email
In a unique approach, Eternidade Stealer connects to an IMAP mailbox where attackers store updated command and control details. By rotating domains through email storage, the operators gain resilience against domain takedowns and security monitoring.
Sophisticated Dropper Operation Under the Hood
The dropper includes AutoIt based scripts that inspect the host environment, detect antivirus software, collect system signatures and decrypt secondary payloads. It checks for prior infection to avoid redundancy, then launches reconnaissance programs that map the system for banking activity.
Key Capabilities Exposed
The malware’s core functions are designed for stealth, speed and adaptability. Its main capabilities include dynamic C2 discovery through IMAP, WhatsApp contact theft, automated message delivery, banking credential interception through overlays, system profiling, process injection and antivirus detection.
Global Footprint Revealed in Backend Logs
Researchers traced the operation to multiple backend domains and management panels used for redirect tracking. Surprisingly, logs showed 454 connection attempts spanning 38 countries. Only a small share originated in Brazil, suggesting that attackers are testing or deploying components outside the region despite a Brazilian focus.
Workstations Targeted Over Mobile Devices
Most visitors accessing the infrastructure used desktop systems. This indicates that the malware was built primarily for traditional workstation environments, not mobile platforms, which aligns with its Windows centric architecture.
High Alert For Defenders
Security teams are urged to monitor for unusual WhatsApp behavior, unexpected MSI installs, suspicious script executions and indicators tied to this campaign. The blending of worm behavior with financial theft marks a dangerous evolution that requires rapid detection and user awareness.
What Undercode Say:
The Strategic Leap Behind Eternidade Stealer
Brazil has long been a hotbed for financially motivated malware, but Eternidade marks a strategic shift. Instead of relying on phishing campaigns or brute force credential theft, attackers are now weaponizing the country’s most popular communication channel. WhatsApp acts not just as a delivery mechanism but as a built in trust factor. Users are far more likely to open files that appear to come from known contacts, especially when messages include their name and personalized greetings. The social engineering angle is almost surgical.
Why Python Based Automation Raises the Stakes
The move to Python for automating WhatsApp interactions is significant. Python lowers development friction and expands access to libraries that make messaging automation trivial. Threat actors no longer need deep expertise to build self spreading malware. They only need to combine existing message automation tools with a dropper capable of delivering a banking Trojan.
IMAP Based Command Retrieval Shows Adaptability
Using an IMAP mailbox for dynamic C2 retrieval is quietly brilliant. Email infrastructure is resilient, widely trusted and rarely blocked at the network level. By storing C2 details inside mailbox messages, attackers bypass detection systems that scan for suspicious domain patterns. This technique gives Eternidade a survival advantage, allowing its operators to refresh infrastructure whenever necessary without redeploying the malware.
Why Localization Enhances Effectiveness
Language locked activation is an increasingly common tactic in region specific financial malware. By restricting activation to Brazilian Portuguese environments, Eternidade reduces global scrutiny, avoids unnecessary detection spikes and focuses solely on profitable targets. Cybercriminals have learned that precision often yields more value than volume.
Attacking Brazil’s Digital Economy With Precision
Banking overlays targeting institutions like Itaú and Bradesco reflect deep research into local user behavior. These overlays mimic real login screens and appear only at the moment of authentication. This level of timing requires careful programming and suggests that the operators understand Brazilian banking flows intimately.
Worm Like Propagation Makes This Threat Hard To Contain
Traditional banking Trojans require users to click harmful links or run infected files. Eternidade bypasses these weaknesses by letting the malware pass itself from contact to contact, almost like a biological virus. The ability to self replicate through trusted social networks turns every infected user into a distribution hub.
Why This Malware Signals a Turning Point
This campaign demonstrates that Brazilian cybercrime is shifting from opportunistic attacks to scalable, automated frameworks. The combination of social engineering, Python automation, dynamic C2 management and financial theft demonstrates an infrastructure that can evolve. Brazil’s financial sector is now facing adversaries who iterate rapidly and adapt like commercial software developers.
Potential Future Evolutions
If attackers expand beyond WhatsApp and integrate Telegram or SMS automation, the threat could multiply. The infrastructure logs showing visitors from 38 countries hint at experimentation. Operators may already be preparing versions targeting other languages or markets.
The Real Risk for Businesses and Individuals
Eternidade is dangerous because it blends trust exploitation with financial theft. It leverages contacts, personalized messaging, workstation access and banking credentials. This cross vector approach makes it one of the most complete financial threats active in the region.
🔍 Fact Checker Results
WhatsApp propagation through Python automation is confirmed by Trustwave research. ✅
Dynamic IMAP C2 retrieval is verified as part of the malware’s resilience strategy. ✅
Targeting of Brazilian banks and fintech apps is consistently documented in multiple forensic samples. ✅
📊 Prediction
Eternidade Stealer will likely evolve into a multilingual, multi region threat within the next year. 🌍
Operators may expand propagation into Telegram or SMS channels as defenses strengthen. 📱
Brazil’s financial institutions will increasingly face malware that blends social engineering with automation. ⚠️
🕵️📝✔️Let’s dive deep and fact‑check.
References:
Reported By: www.infosecurity-magazine.com
Extra Source Hub (Possible Sources for article):
https://www.facebook.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
Bing
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon




