Concise Cyber

Subscribe below for free to get these delivered straight to your inbox

Advertisements
Eternidade Stealer: Python Worm Exploits WhatsApp to Target Brazilian Users
Advertisements

A cybersecurity campaign has been identified targeting users in Brazil with a Python-based worm that spreads the Eternidade information stealer. The malware propagates through the popular messaging application WhatsApp, leveraging victims’ own accounts to reach new targets. The operation is linked to a threat actor known as the “Enigma Team,” which sells the Eternidade malware as a service on a subscription basis.

Infection and Propagation Mechanism

The attack chain begins when a user receives a malicious message on WhatsApp from an already compromised contact. This message contains a link that, when clicked, downloads a VBScript file. Execution of this script initiates the download of a .NET loader, which is the primary component responsible for installing the malware payloads. This loader deploys two main components onto the victim’s system: the Eternidade information stealer and the Python-based worm. The worm component then gains access to the victim’s active WhatsApp for Web session. It uses this access to automatically send the same malicious message to the victim’s contact list, thereby continuing the infection cycle.

Capabilities of the Eternidade Stealer

Once active on a system, the Eternidade stealer is designed to exfiltrate a wide range of sensitive data. Its documented capabilities include stealing saved credentials, cookies, and credit card information from popular web browsers such as Google Chrome, Mozilla Firefox, and Microsoft Edge. The malware also targets cryptocurrency wallets, including Exodus, Atomic, and MetaMask, to steal wallet data. Additional functions include stealing files from the user’s desktop, capturing screenshots of the active screen, and logging keystrokes. The stealer has also been observed exfiltrating credentials from FTP clients like FileZilla and email clients like Thunderbird.

All articles are written here with the help of AI on the basis of openly available information which cannot be independently verified. We do strive to quote the relevant sources.The intent is only to summarise what is already reported in public forum in our own wordswith no intention to plagarise or copy other person’s work.The publisher has no intent to defame or cause offence to anyone, any person or any organisation at any moment.The publisher assumes no responsibility for any damage or loss caused by making decisions on the basis of whatever is published on cyberconcise.com.You’re advised to do your own checks and balances before making any decision, and owners and publishers at cyberconcise.com cannot be held accountable for its resulting ramifications.If you have any objections, concerns or point out anything factually incorrect, please reach out using the form on https://concisecyber.com/about/

Discover more from Concise Cyber

Subscribe now to keep reading and get access to the full archive.

Continue reading