Skip to main content

Threats Tagged 'maverick'

View all threats tagged with 'maverick'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: maverick

Threats Tagged 'maverick'

Click on any threat for detailed analysis and mitigation recommendations

A sophisticated Brazilian banking trojan named TCLBANKER has been identified, representing a significant evolution of the MAVERICK/SORVEPOTEL malware family. The campaign employs a trojanized Logitech installer that deploys two .NET Reactor-protected modules through DLL side-loading. The banking trojan monitors 59 Brazilian financial institutions using UI Automation and features a WPF-based full-screen overlay framework for operator-driven social engineering attacks, including credential harvesting and fake system screens. A secondary worm module enables self-propagation through WhatsApp session hijacking and Outlook COM automation, sending phishing messages from victims' own accounts. The malware implements robust anti-analysis capabilities including environment-gated payload decryption, comprehensive watchdog systems, and ETW patching. Infrastructure is hosted on Cloudflare Workers, with evidence suggesting the campaign was detected in early operational stages.

Join the discussion

A malware campaign targeting WhatsApp users primarily in Brazil uses WhatsApp's 'View Once' message feature to deliver malicious ZIP archives containing VBS or HTA files. These files execute PowerShell scripts to download additional payloads, including scripts that steal WhatsApp user data and an MSI installer deploying the Astaroth banking trojan. The campaign evolved from IMAP-based to HTTP-based command and control communication and leverages Selenium Chrome WebDriver and the WPPConnect JavaScript library to hijack WhatsApp Web sessions, steal session tokens and contacts, and distribute spam. Over 250 victims have been identified, with 95% located in Brazil and some impact noted in Austria. The attack enables credential theft, session hijacking, persistence, and financial fraud through banking trojan deployment. No CVE or known exploits in the wild are reported, and the campaign is rated medium severity. Defenders should focus on user awareness, endpoint detection of PowerShell and script execution, and monitoring for suspicious WhatsApp Web activity.

Join the discussion

This intelligence report examines the connection between two Brazilian banking trojans, Maverick and Coyote. The malware spreads through WhatsApp, using a multi-stage attack that begins with a malicious LNK file. Both trojans share similarities in their infection methods, targeting Brazilian users and banks. The attack chain involves obfuscated PowerShell commands, downloading additional payloads from command and control servers. The malware employs anti-analysis techniques and targets specific browsers. Persistence is achieved through a batch file in the startup folder. The report provides technical details, including code samples and infection chain analysis, as well as indicators of compromise for the identified malware campaign.

Join the discussion

A new banking Trojan named Maverick has emerged, targeting Brazilian users through a massive WhatsApp distribution campaign. The infection chain begins with a malicious LNK file sent via WhatsApp, leading to a complex, fileless infection process. Maverick uses the WPPConnect project to automate message sending from hijacked accounts, spreading the malware further. The Trojan monitors 26 Brazilian bank websites, 6 cryptocurrency exchanges, and 1 payment platform, aiming to capture banking credentials. It employs advanced evasion techniques, including AI-assisted code development, and shares similarities with the Coyote banking Trojan. The campaign's impact is significant due to its worm-like nature and exploitation of a popular messaging platform.

Join the discussion

Showing 1 to 4 of 4 results

Filters:Tag: maverick
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses