Skip to main content

Threats Tagged 'sorvepotel'

View all threats tagged with 'sorvepotel'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: sorvepotel

Threats Tagged 'sorvepotel'

Click on any threat for detailed analysis and mitigation recommendations

A sophisticated Brazilian banking trojan named TCLBANKER has been identified, representing a significant evolution of the MAVERICK/SORVEPOTEL malware family. The campaign employs a trojanized Logitech installer that deploys two .NET Reactor-protected modules through DLL side-loading. The banking trojan monitors 59 Brazilian financial institutions using UI Automation and features a WPF-based full-screen overlay framework for operator-driven social engineering attacks, including credential harvesting and fake system screens. A secondary worm module enables self-propagation through WhatsApp session hijacking and Outlook COM automation, sending phishing messages from victims' own accounts. The malware implements robust anti-analysis capabilities including environment-gated payload decryption, comprehensive watchdog systems, and ETW patching. Infrastructure is hosted on Cloudflare Workers, with evidence suggesting the campaign was detected in early operational stages.

Join the discussion

A phishing campaign targeting Brazilian users spreads a banking trojan via WhatsApp Web by leveraging an open-source automation script. The attack starts with a malicious VBS script in a phishing email that downloads and executes an MSI installer and another VBS script. The second VBS installs Python and Selenium to inject malicious JavaScript into WhatsApp Web, enabling the malware to propagate by sending itself to the victim's contacts. The MSI drops an AutoIt script that monitors for Brazilian banking and cryptocurrency application windows and loads an encrypted payload into memory to evade detection. This payload specifically targets Brazilian financial institutions and cryptocurrency wallets. The campaign uses in-memory execution and automation to maintain stealth and persistence. No known exploits in the wild have been reported yet, and the campaign is currently assessed as medium severity. The attack is highly tailored to Brazilian users and financial targets but could pose risks if similar tactics spread elsewhere.

Join the discussion

The Water Saci campaign is a sophisticated malware operation targeting Portuguese-language systems, leveraging WhatsApp Web hijacking and multi-vector persistence mechanisms. It uses script-based techniques such as VBS downloaders and PowerShell scripts to automate malware distribution and maintain resilience. The campaign employs an email-based command and control infrastructure using IMAP for command retrieval, supplemented by HTTP polling for continuous communication. It features advanced anti-analysis capabilities and real-time remote control, enabling infected machines to operate as a coordinated botnet. The malware shares similarities with the Coyote banking trojan, indicating ties to Brazilian cybercriminal groups. Although no known exploits are reported in the wild, the campaign's complexity and persistence mechanisms pose a medium-level threat. European organizations with Portuguese-speaking user bases or connections to Brazil should be particularly vigilant. Mitigation requires targeted detection of script-based loaders, monitoring of WhatsApp Web session anomalies, and securing email clients against unauthorized IMAP access. Countries with strong economic or cultural ties to Brazil, such as Portugal and Spain, are most likely to be affected.

Join the discussion

SORVEPOTEL has been observed to spread across Windows systems through convincing phishing messages with malicious ZIP file attachments. Interestingly, the phishing message that contains the malicious file attachment requires users to open it on a desktop, suggesting that threat actors might be more interested in targeting enterprises rather than consumers. Once opened, the malware automatically propagates via WhatsApp Web, causing infected accounts to be banned due to excessive spam activity.

Join the discussion

Showing 1 to 4 of 4 results

Filters:Tag: sorvepotel
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses