Water Saci is a sophisticated Brazilian threat actor targeting the financial sector with WhatsApp social engineering and multi-format attack chains to deliver the SORVEPOTEL banking trojan.
Analyst brief
Water Saci is a sophisticated threat actor operating in Brazil that evades security measures using a multi-format attack chain involving HTA, ZIP, and PDF files. They primarily target the financial sector and leverage social engineering via WhatsApp to propagate the SORVEPOTEL banking trojan. Their TTPs include an email-based C2 infrastructure through IMAP connections to terra.com.br accounts, multi-format payload delivery, and a modular malware architecture for dynamic adaptation. Defenders should focus on monitoring suspicious email attachments, inspecting IMAP traffic for anomalies, and reinforcing defenses against multi-stage file formats.
Water Saci
unknown
Water Saci is a sophisticated cyber threat actor operating in Brazil, utilizing a multi-format attack chain that includes HTA files, ZIP archives, and PDFs to bypass security measures. The campaign employs an email-based C&C infrastructure using IMAP connections to terra.com.br accounts, enhancing its resilience and evasion tactics. It leverages social engineering through WhatsApp to propagate malware, specifically the SORVEPOTEL banking trojan, and incorporates advanced techniques for infection and persistence. The modular architecture of the malware allows for dynamic adaptation and extraction of sensitive credentials, indicating a significant evolution in adversarial capabilities.