The Containment Era is here. →Explore

Executive Summary

In November 2025, cybersecurity researchers identified a sophisticated campaign targeting Brazilian users via WhatsApp, where attackers leveraged a Python-based worm combined with social engineering tactics. Victims were tricked into installing a worm that hijacked WhatsApp sessions and propagated itself to contacts, while delivering a Delphi-based banking trojan known as Eternidade Stealer. The campaign exploited IMAP to dynamically resolve command-and-control infrastructure, enabling threat actors to orchestrate info-stealing and credential harvesting at scale and with resilience to takedown attempts. The incident had significant implications for financial fraud and impacted numerous personal and business WhatsApp accounts across Brazil.

This campaign is emblematic of a wider surge in malware leveraging messaging platforms for lateral movement and rapid propagation. The popularity of WhatsApp, combined with increasingly modular infostealers and TTP reuse by criminal groups, highlights the urgent need for proactive controls and visibility across both east-west and outbound communication paths.

Why This Matters Now

The rapid propagation of infostealers via widely used communication tools like WhatsApp exposes organizations and individuals to increased credential compromise and financial loss. As attackers exploit trusted platforms and social connections to bypass perimeter defenses, businesses must urgently enhance security controls to detect lateral movement and implement segmentation strategies before such techniques become mainstream.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Attackers used a Python-based worm to hijack compromised users’ WhatsApp clients and send malicious payloads to their contacts, rapidly expanding the infection.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Zero Trust Segmentation, egress controls, east-west traffic security, and inline threat detection would have significantly constrained the attacker's ability to propagate, communicate externally, and exfiltrate data. Applying these controls could have contained the infection to initial hosts, prevented unauthorized outbound traffic, and provided early detection of anomalous activity.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Attack surface reduced via inline inspection and distributed enforcement.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Unauthorized attempts for privilege gain disrupted by least privilege policy.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Lateral propagation attempts detected and blocked.

Command & Control

Control: Cloud Firewall (ACF)

Mitigation: Malicious outbound connections prevented.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Sensitive data exfiltration attempts detected and blocked.

Impact (Mitigations)

Rapid alerting and incident response minimize business and privacy impact.

Impact at a Glance

Affected Business Functions

  • Customer Communications
  • Financial Transactions
  • Data Security
Operational Disruption

Estimated downtime: 5 days

Financial Impact

Estimated loss: $500,000

Data Exposure

Potential exposure of customer contact information, financial credentials, and personal data due to malware propagation through WhatsApp.

Recommended Actions

  • Enforce identity-based Zero Trust Segmentation to restrict lateral movement across internal cloud and hybrid environments.
  • Deploy robust inline egress controls to detect and block malicious outbound connections, exfiltration attempts, and unauthorized protocol usage.
  • Implement distributed anomaly detection and real-time incident response to identify abnormal behaviors linked to malware activity.
  • Ensure high-performance encryption is in place for all data in transit to prevent interception or manipulation by adversaries.
  • Centralize multicloud visibility and policy enforcement to rapidly triage threats and reduce attack dwell time.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image