The Containment Era is here. →Explore

Executive Summary

In late 2025, Brazil was struck by a sophisticated banking trojan campaign perpetrated by the threat actor Water Saci. Leveraging WhatsApp as a wormable transmission channel, attackers delivered highly obfuscated HTA and PDF payloads to users. Once opened, these files initiated a new Python-based trojan variant, enabling credential theft and fraudulent banking transactions. The attack chain also included NFC relay tactics (RelayNFC), amplifying transactional fraud by hijacking contactless payment operations. The campaign evaded detection using advanced scripting and lateral propagation, causing financial and reputational damage within the Brazilian financial sector.

This incident marks a significant escalation in multichannel malware delivery, combining social engineering, banking trojans, and NFC payment interception. It underscores the converging risk between consumer messaging apps and new payment technologies, highlighting the urgency for layered east-west and egress network protection.

Why This Matters Now

The attack highlights an urgent need for organizations to secure not only conventional endpoints but also mobile messaging channels and NFC-enabled systems. With banking trojans increasingly leveraging trusted communication apps and exploiting contactless payment infrastructures, financial institutions must adopt comprehensive, zero trust controls to curb evolving threats targeting both digital and physical transaction flows.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The incident highlighted deficits in data-in-transit protections, east-west traffic control, and centralized visibility, pushing the need for ZTMM and modern PCI/NIST network controls.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Network segmentation, east-west traffic controls, egress filtering, and real-time threat detection could have isolated compromised workloads, limited malware propagation, and blocked data exfiltration. Zero Trust-driven microsegmentation and policy enforcement restrict attacker lateral movement and detect anomalous egress activities tied to banking trojans.

Initial Compromise

Control: Cloud Firewall (ACF)

Mitigation: Inbound and outbound network filtering blocks unauthorized or known-malicious traffic sources.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Limits attacker access to privileged resources based on identity and least privilege.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Internal movement between workloads is monitored and restricted to only authorized communications.

Command & Control

Control: Inline IPS (Suricata)

Mitigation: Malicious C2 traffic is detected and blocked in real-time.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Outbound communication to unapproved destinations is prevented and flagged for response.

Impact (Mitigations)

Rapid detection of fraudulent behaviors enables incident response before system-wide damage.

Impact at a Glance

Affected Business Functions

  • Online Banking Services
  • Customer Support
Operational Disruption

Estimated downtime: 3 days

Financial Impact

Estimated loss: $500,000

Data Exposure

Potential exposure of customer banking credentials and personal information due to malware infection.

Recommended Actions

  • Implement Zero Trust Segmentation to strictly limit account lateral movement post-compromise.
  • Enforce egress policies with granular FQDN filtering to prevent malware C2 and data exfiltration.
  • Deploy Inline IPS and continuous threat detection to rapidly identify and respond to banking trojan behaviors.
  • Strengthen east-west traffic monitoring to block unauthorized internal communications.
  • Regularly update endpoint and cloud workload posture controls to thwart evolving phishing and malware delivery methods.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image