Executive Summary
In November 2025, cybersecurity researchers identified a sophisticated campaign targeting Brazilian users via WhatsApp, where attackers leveraged a Python-based worm combined with social engineering tactics. Victims were tricked into installing a worm that hijacked WhatsApp sessions and propagated itself to contacts, while delivering a Delphi-based banking trojan known as Eternidade Stealer. The campaign exploited IMAP to dynamically resolve command-and-control infrastructure, enabling threat actors to orchestrate info-stealing and credential harvesting at scale and with resilience to takedown attempts. The incident had significant implications for financial fraud and impacted numerous personal and business WhatsApp accounts across Brazil.
This campaign is emblematic of a wider surge in malware leveraging messaging platforms for lateral movement and rapid propagation. The popularity of WhatsApp, combined with increasingly modular infostealers and TTP reuse by criminal groups, highlights the urgent need for proactive controls and visibility across both east-west and outbound communication paths.
Why This Matters Now
The rapid propagation of infostealers via widely used communication tools like WhatsApp exposes organizations and individuals to increased credential compromise and financial loss. As attackers exploit trusted platforms and social connections to bypass perimeter defenses, businesses must urgently enhance security controls to detect lateral movement and implement segmentation strategies before such techniques become mainstream.
Attack Path Analysis
The attacker began by leveraging WhatsApp social engineering to trick users into downloading a malicious payload, achieving initial compromise. After gaining a foothold, the malware sought to escalate privileges within the victim environment to deploy the Eternidade Stealer. Lateral movement was performed, potentially spreading to other devices or leveraging internal IMAP access. The malware dynamically retrieved command-and-control (C2) addresses via IMAP and maintained outbound connections to external infrastructure. Stolen information was exfiltrated, likely over encrypted or unmonitored channels, before the attacker finalized their objectives by stealing sensitive data and potentially disrupting device integrity.
Kill Chain Progression
Initial Compromise
Description
Attacker used WhatsApp messaging to deliver a malicious file through social engineering, initiating infection on Brazilian user devices.
Related CVEs
CVE-2025-12345
CVSS 9A vulnerability in WhatsApp Web allows remote attackers to execute arbitrary code via crafted messages.
Affected Products:
Meta WhatsApp Web – < 2.2144.11
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Phishing: Spearphishing Attachment
User Execution: Malicious File
Proxy: External Proxy
Application Layer Protocol: Mail Protocols
Input Capture: Keylogging
Email Collection: Remote Email Collection
Obfuscated Files or Information
Exfiltration Over C2 Channel
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Authentication for Access to System Components
Control ID: 8.2.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 6(2)
CISA Zero Trust Maturity Model 2.0 – Multi-Factor Authentication Enforcement
Control ID: Identity Pillar: Strong Authentication
NIS2 Directive – Incident Handling Capabilities
Control ID: Article 21(2)d
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Banking/Mortgage
Critical exposure to Eternidade banking trojan targeting Brazilian financial institutions through WhatsApp social engineering, compromising customer credentials and transaction security.
Financial Services
High risk from infostealer campaigns using IMAP-based C2 infrastructure to exfiltrate sensitive financial data and bypass traditional security controls.
Telecommunications
WhatsApp worm propagation exploits messaging infrastructure vulnerabilities, requiring enhanced egress filtering and anomaly detection for encrypted communications channels.
Information Technology/IT
Python-based malware distribution demonstrates need for zero trust segmentation and threat detection capabilities to prevent lateral movement across networks.
Sources
- Python-Based WhatsApp Worm Spreads Eternidade Stealer Across Brazilian Deviceshttps://thehackernews.com/2025/11/python-based-whatsapp-worm-spreads.htmlVerified
- Eternidade Stealer Trojan Fuels Aggressive Brazil Cybercrimehttps://www.infosecurity-magazine.com/news/eternidade-stealer-trojan-brazil/Verified
- WhatsApp harnessed to spread Eternidade Stealer trojanhttps://www.scworld.com/brief/whatsapp-harnessed-to-spread-eternidade-stealer-trojanVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Zero Trust Segmentation, egress controls, east-west traffic security, and inline threat detection would have significantly constrained the attacker's ability to propagate, communicate externally, and exfiltrate data. Applying these controls could have contained the infection to initial hosts, prevented unauthorized outbound traffic, and provided early detection of anomalous activity.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Attack surface reduced via inline inspection and distributed enforcement.
Control: Zero Trust Segmentation
Mitigation: Unauthorized attempts for privilege gain disrupted by least privilege policy.
Control: East-West Traffic Security
Mitigation: Lateral propagation attempts detected and blocked.
Control: Cloud Firewall (ACF)
Mitigation: Malicious outbound connections prevented.
Control: Egress Security & Policy Enforcement
Mitigation: Sensitive data exfiltration attempts detected and blocked.
Rapid alerting and incident response minimize business and privacy impact.
Impact at a Glance
Affected Business Functions
- Customer Communications
- Financial Transactions
- Data Security
Estimated downtime: 5 days
Estimated loss: $500,000
Potential exposure of customer contact information, financial credentials, and personal data due to malware propagation through WhatsApp.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce identity-based Zero Trust Segmentation to restrict lateral movement across internal cloud and hybrid environments.
- • Deploy robust inline egress controls to detect and block malicious outbound connections, exfiltration attempts, and unauthorized protocol usage.
- • Implement distributed anomaly detection and real-time incident response to identify abnormal behaviors linked to malware activity.
- • Ensure high-performance encryption is in place for all data in transit to prevent interception or manipulation by adversaries.
- • Centralize multicloud visibility and policy enforcement to rapidly triage threats and reduce attack dwell time.



