A new malware wave in Brazil uses WhatsApp Web sessions to spread banking trojans and steal contact data. Attackers begin with phishing emails that deliver heavily obfuscated VBS scripts designed to evade detection. The payload installs Python, Selenium, and ChromeDriver to automate WhatsApp Web without user involvement. The malware hijacks logged-in sessions, injects malicious JavaScript, and sends infected files to every reachable contact.
Relevant Source (Trend Micro Research): Self Propagating Malware Spreading Via WhatsApp Targets Brazilian Users
Trend Micro documents a Brazil focused WhatsApp campaign that hijacks active sessions, auto sends malicious ZIPs to contacts, and deploys malware tied to the Water Saci operation.
Quick Facts
- Campaign targets Brazilian users through phishing emails.
- Malware abuses logged-in WhatsApp Web sessions by copying browser data.
- Python and Selenium handle full automation of messaging and contact harvesting.
- Banking trojan activates when Brazilian bank windows are detected.
- Memory-only execution avoids traditional antivirus scanning.
- Identified as a variant of the Water Saci financial malware family.
How The Attack Works
The campaign begins with ZIP files containing VBS scripts that reconstruct malicious code through character building and XOR decoding. After unpacking, the script downloads an MSI file and a second VBS stage that installs Python and Selenium to prepare automated browser control. The malware copies browser cookies and storage files to impersonate the victim and open WhatsApp Web without scanning a QR code. It then injects JavaScript to access WhatsApp’s internal APIs and harvest contacts.
Key Points:
- Uses heavy VBS obfuscation to hide commands.
- Bypasses WhatsApp authentication by copying Chrome profile data.
- Injects helper scripts to enumerate contacts and send malicious files.
A closing look at the flow shows a layered setup that blends social engineering with browser automation, giving attackers control over both messaging and credential harvesting.
Relevant Source (SecurityOnline.info / K7 Labs): Brazilian Banking Trojan Uses Python WhatsApp Worm and IMAP C2 for In-Memory Credential Theft
This writeup summarizes K7 Labs’ analysis of a Water Saci variant that uses obfuscated VBS, MSI and VBS stages, Python, ChromeDriver, and WhatsApp Web session hijacking to harvest contacts and spread banking malware.
Security Impact
The malware exploits trusted communication channels, which makes victims more likely to open malicious attachments. It targets financial institutions and crypto wallets by monitoring active windows and loading a banking trojan directly into memory when specific triggers appear. This memory-based loading reduces forensic evidence and complicates detection. The campaign spreads quickly because each infected host relays malware to every valid WhatsApp contact.
Key Risks:
- Compromises online banking and crypto wallets.
- Evades signature detection through obfuscation.
- Replicates rapidly across personal and business networks.
- Hijacks authenticated sessions without user permission.
- Establishes persistence via registry modifications and AutoIt scripts.
The broader effect is an expanding infection chain that abuses personal relationships, undermining trust in day-to-day communication tools.
Relevant Source (Brave New Coin): WhatsApp Worm Spreads Banking Trojan Across Brazil, Targets Crypto Wallets
This report covers a WhatsApp worm that deploys banking trojans against Brazilian bank and crypto users, highlighting risks to financial accounts and the rapid spread across trusted social graphs.
Protective Steps
Users can limit exposure by treating unsolicited ZIP or script files as high risk, even if they appear to come from known contacts. Security teams should block VBS scripts by default, enforce least-privilege access, and monitor for browser automation tools like ChromeDriver on endpoints. Systems that handle financial data benefit from segmentation and real-time monitoring of unusual browser activity.
Recommended Actions:
- Disable execution of VBS and script files from email sources.
- Enable MFA on WhatsApp and all financial platforms.
- Scan systems for Python and Selenium installations not used legitimately.
- Review browser profiles for unauthorized duplication.
- Apply updates and endpoint protection tuned for memory-based threats.
Following these steps reduces the risk of session hijacking and limits the chances of malware spreading through trusted channels.
Relevant Source (MITRE ATT&CK): Command And Scripting Interpreter: Visual Basic
MITRE documents how attackers abuse VBScript in email attachments and scripts, supporting the recommendation to block or downgrade VBS execution from mail sources.
Relevant Source (WhatsApp Help Center): How To Manage Two Step Verification Settings
WhatsApp’s official guidance explains enabling two step verification, reinforcing the advice to use MFA to protect accounts that could be abused in these campaigns.
The Big Picture
The Water Saci campaign reflects a shift toward attacks that mix social engineering, legitimate automation tools, and session hijacking. This blend allows attackers to bypass security measures that rely on behavioral flags or file scanning. The use of WhatsApp as a distribution vector also shows how messaging platforms are becoming high-value targets because users rarely question files sent by their own contacts.
Banking trojans continue to evolve in ways that avoid writing permanent files, making memory inspection more important for defenders. Financial institutions in Brazil remain frequent targets due to high online banking adoption, but the techniques used here can expand globally. The combination of Python automation, browser profile theft, and internal API abuse is particularly flexible and can be repurposed by other threat actors.
Relevant Source (Trend Micro Research): Active Water Saci Campaign Spreading Via WhatsApp Features Multi-Vector Persistence And Sophisticated C&C
Trend Micro tracks the evolving Water Saci operation, describing how it abuses WhatsApp, multi vector persistence, and flexible infrastructure to sustain large scale campaigns in Brazil.
Relevant Source (IBM Security X-Force): PixPirate: The Brazilian Financial Malware You Can’t See
IBM analyzes PixPirate, a Brazilian financial malware family that focuses on stealth and limited disk artifacts, highlighting the broader move toward hard to detect banking trojans in the region.
Closing Guidance
Staying safe requires a mix of cautious behavior and strong technical safeguards. Phishing remains the attacker’s entry point, and any script-based file arriving by email should be considered hostile. Regular security checks and trusted security tools help reduce the likelihood of silent session hijacking.
Common Questions
How does the malware access WhatsApp without a QR code?
It copies the victim’s browser cookies and storage data, then loads WhatsApp Web through Selenium using the stolen profile.
Why does it target Brazil?
Brazilian banks and payment apps are frequent targets of financial malware families like Water Saci.
Can this attack spread outside WhatsApp?
Yes. The banking trojan portion monitors desktop activity and can target any financial or wallet application it recognizes.
Does antivirus detect this malware?
Detection is difficult because obfuscated VBS, Python automation, and memory-only payloads reduce traditional signatures.
What signs indicate infection?
Unexpected Python or Selenium processes, WhatsApp messages you did not send, and browser profile duplication are strong indicators.
How JENI Strengthens Everyday Cyber Defense
JENI supports users who want a cleaner, faster, and safer system without juggling complex tools. The platform improves system stability, reduces hidden resource drains, and helps prevent the slowdowns that often mask early-stage malware activity. Solid performance hygiene is a practical first line of defense when attackers rely on stealthy tools that blend into normal processes.
Key Advantages
- Reduces unnecessary background processes that attackers often exploit.
- Helps maintain a stable environment where suspicious changes stand out.
- Supports cleaner system baselines that improve threat visibility.
A consistent maintenance routine limits the blind spots attackers count on when deploying browser automation, session hijacking, or memory-only payloads. A well-optimized system makes abnormal behavior easier to detect before financial or personal data is exposed. Security products remain important, yet overall system health plays a quiet but critical role in resilience. JENI fills that gap by strengthening the foundation attackers rely on to stay hidden.

