⤷ Title: Maverick Fileless Trojan Turns Infected Phones into WhatsApp Worms to Steal Banking and UPI Credentials
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 00:06:23 +0000
════════════════════════
⌗ Tags: #Malware #Banking Trojan #Brazil #Fileless Malware #Maverick #Self_Propagation #UPI Fraud #WhatsApp #WPPConnect
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 00:06:23 +0000
════════════════════════
⌗ Tags: #Malware #Banking Trojan #Brazil #Fileless Malware #Maverick #Self_Propagation #UPI Fraud #WhatsApp #WPPConnect
Daily CyberSecurity
Maverick Fileless Trojan Turns Infected Phones into WhatsApp Worms to Steal Banking and UPI Credentials
Kaspersky exposed Maverick, a sophisticated fileless banking Trojan targeting Brazil. It hijacks WhatsApp Web using WPPConnect for self-propagation and installs phishing overlays to steal UPI/banking data.
⤷ Title: Sophisticated WhatsApp Worm Uses Fake “View Once” Lure to Hijack Sessions and Deploy Astaroth Banking Trojan
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 00:33:37 +0000
════════════════════════
⌗ Tags: #Malware #Astaroth #Banking Trojan #Selenium #Session Hijacking #STAC3150 #VBScript #WhatsApp #WPPConnect
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 00:33:37 +0000
════════════════════════
⌗ Tags: #Malware #Astaroth #Banking Trojan #Selenium #Session Hijacking #STAC3150 #VBScript #WhatsApp #WPPConnect
Daily CyberSecurity
Sophisticated WhatsApp Worm Uses Fake "View Once" Lure to Hijack Sessions and Deploy Astaroth Banking Trojan
Sophos exposed STAC3150, a campaign using fake "View Once" messages to deploy Astaroth banking trojan. The malware hijacks WhatsApp Web sessions via WPPConnect/Selenium for self-propagation.
⤷ Title: Brazilian Banking Trojan Uses Python WhatsApp Worm and IMAP C2 for In-Memory Credential Theft
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 25 Nov 2025 00:11:04 +0000
════════════════════════
⌗ Tags: #Malware #AutoIt Loader #Brazilian Banking Trojan #IMAP C2 #In_Memory Injection #Python #WhatsApp Worm #WPPConnect
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 25 Nov 2025 00:11:04 +0000
════════════════════════
⌗ Tags: #Malware #AutoIt Loader #Brazilian Banking Trojan #IMAP C2 #In_Memory Injection #Python #WhatsApp Worm #WPPConnect
Daily CyberSecurity
Brazilian Banking Trojan Uses Python WhatsApp Worm and IMAP C2 for In-Memory Credential Theft
K7 Labs exposed a Brazilian campaign using a Python WhatsApp worm for self-propagation. The in-memory AutoIt loader deploys a banking trojan that uses IMAP email as a covert C2 channel to steal banking credentials.