The Containment Era is here. →Explore

Executive Summary

In early June 2024, an infostealer campaign dubbed Water Saci aggressively targeted WhatsApp users in Brazil using self-propagating malware named Sorvepotel. Attackers leveraged compromised accounts to automatically distribute malicious links via WhatsApp messages, luring recipients to execute malware payloads. Once installed, Sorvepotel exfiltrates credentials and tracks browser activities, enabling threat actors to target and defraud regional financial institutions. The infection chain’s ability to rapidly spread through trusted social contacts increased both the velocity and scale of impact, compromising both individual and enterprise devices in a short time frame.

The Water Saci operation highlights the evolution of credential-stealing malware adopting worm-like features to maximize reach. With messaging platforms remaining core to business and personal communications, this incident underscores the urgency of intercepting lateral movement, especially as attackers blend social engineering with advanced propagation and data theft techniques.

Why This Matters Now

The surge of self-propagating infostealers like Sorvepotel demonstrates how messaging platforms are now primary vectors for widespread credential theft and financial fraud. Organizations operating in and with Brazil face heightened risk because such attacks bypass traditional defenses and rapidly exploit trust relationships, making quick detection and response more critical than ever.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The campaign exploited weaknesses in east-west traffic security, identity-based policy segmentation, and lack of robust egress policy enforcement on enterprise and personal devices.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Zero Trust segmentation, East-West traffic control, egress policy enforcement, and advanced threat detection would have significantly reduced the attack's blast radius, interrupted lateral movement, and detected or blocked credential exfiltration attempts. CNSF-aligned controls implemented at the network and workload level can disrupt self-propagating malware and prevent data loss.

Initial Compromise

Control: Threat Detection & Anomaly Response

Mitigation: Early detection of unusual inbound or application traffic patterns.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Restricted malware movement with least privilege and microsegmentation.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Blocked unauthorized internal traffic and lateral spread attempts.

Command & Control

Control: Cloud Firewall (ACF) with Inline IPS

Mitigation: Prevented malicious C2 channels and outbound callbacks.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Prevented sensitive data exfiltration via enforced outbound policies.

Impact (Mitigations)

Provided rapid visibility for response and containment post-exfiltration.

Impact at a Glance

Affected Business Functions

  • Financial Transactions
  • Customer Communications
  • Data Security
Operational Disruption

Estimated downtime: 3 days

Financial Impact

Estimated loss: $500,000

Data Exposure

Potential exposure of sensitive financial credentials and personal information due to malware's capability to monitor browser activity and steal credentials.

Recommended Actions

  • Implement Zero Trust segmentation and microsegmentation to restrict malware movement across workloads and identities.
  • Enforce egress filtering and outbound policy controls to prevent exfiltration of sensitive data.
  • Deploy advanced threat detection and anomaly response capabilities to identify phishing and self-propagating malware quickly.
  • Enable inline IPS and firewalling to block known malicious C2 and exploit traffic both at the perimeter and internally.
  • Maintain centralized and real-time multicloud visibility to rapidly detect incidents and support active response and recovery.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image