The Containment Era is here. →Explore

Executive Summary

In November 2025, cybersecurity researchers identified a new banking malware called Maverick targeting users in Brazil via malicious WhatsApp messages. Leveraging similarities to the known Coyote strain, Maverick is written in .NET and specifically attacks customers of major Brazilian banks. The malware deceives users into installing it, then hijacks browser sessions, intercepts banking credentials, and enables real-time monitoring of financial transactions to facilitate fraud. This attack underscores the growing sophistication of financially-motivated threats exploiting popular messaging platforms as infection vectors, while leveraging encrypted communications to bypass traditional security controls.

This incident is indicative of a rising trend in banking malware that utilizes encrypted and social engineering channels, challenging established security models. It highlights the need for organizations—particularly in financial services—to adopt advanced detection, segmentation, and encrypted traffic monitoring to reduce the impact of evolving threats.

Why This Matters Now

Banking-focused malware like Maverick threatens the security of financial transactions by exploiting widely used platforms such as WhatsApp, making detection and response challenging. With attackers continuously adapting malware to evade controls and hijack user sessions, proactive measures are urgently needed to protect digital banking customers and meet stringent regulatory compliance requirements.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The attack revealed shortcomings in secure encrypted traffic inspection, east-west security, and real-time threat detection for organizations handling sensitive financial data.

Cloud Native Security Fabric Mitigations and ControlsCNSF

CNSF capabilities such as network segmentation, strict egress policy, encrypted traffic enforcement, and layered threat detection would have limited malware propagation, prevented unauthorized outbound data transfer, and enabled rapid detection and containment of the Maverick attack. Zero Trust controls further restrict lateral movement and session hijacking within the cloud perimeter.

Initial Compromise

Control: Threat Detection & Anomaly Response

Mitigation: Early detection of anomalous user or device activity related to malware delivery.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Limits the scope of compromised credentials and session abuse.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Restricts unauthorized internal communication and lateral spread.

Command & Control

Control: Egress Security & Policy Enforcement

Mitigation: Automated blocking of unapproved outbound C2 communications.

Exfiltration

Control: Cloud Firewall (ACF) & Inline IPS (Suricata)

Mitigation: Detects and blocks unusual outbound data flows and signatures.

Impact (Mitigations)

Rapid detection, segmentation, and automated response minimizes damage.

Impact at a Glance

Affected Business Functions

  • Online Banking
  • Customer Support
  • Fraud Detection
Operational Disruption

Estimated downtime: 5 days

Financial Impact

Estimated loss: $5,000,000

Data Exposure

Potential exposure of customer banking credentials, personal information, and financial data due to credential theft and session hijacking.

Recommended Actions

  • Implement network-wide Zero Trust segmentation to contain malware to its initial entry point and prevent lateral spread.
  • Enforce strong egress security policies with centralized FQDN and IP filtering to block C2 and exfiltration traffic.
  • Enable inline IPS and anomaly detection for real-time monitoring and automated response to suspicious activity and malware indicators.
  • Ensure robust encryption for all data in transit, especially between workloads, to mitigate credential theft and session hijacking.
  • Maintain continuous multicloud visibility and incident response readiness to quickly isolate infected sessions and restore operations.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image