Threat Intelligence, Malware

More sophisticated Water Saci attack methods uncovered

Smartphone with whatsapp icons. 3d rendering

Threat operation Water Saci has exploited WhatsApp to spread HTML Application files and PDFs that facilitate banking trojan compromise in attacks against Brazilian users, according to The Hacker News.

Trusted WhatsApp contacts have been impersonated by attackers to lure victims into clicking the malicious attachments, with the HTA files enabling the execution of a Visual Basic Script that subsequently retrieves an MSI installer for the trojan and a Python script that improves upon the operation's PowerShell-based script for further malware infections, a report from Trend Micro revealed.

Only after verifying that the targeted system has not been previously compromised, checking antivirus software, and gathering system metadata would the Casbaneiro-like banking trojan be executed. Aside from evading analysis and detection via "aggressive" anti-virtualization methods and forcibly ending browser operations, the banking trojan also enables system data exfiltration, keyboard and screen capturing, mouse movement simulations, and file operations.

"This campaign demonstrates how legitimate platforms can be transformed into powerful vectors for malware delivery and underscores the growing sophistication of cybercriminal operations in the region," researchers added.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds