Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Financially Motivated🇧🇷 BR5 malware families

Water Saci

Also known aswater_saci

Water Saci is a financially motivated cybercrime threat actor primarily active in Brazil. It is also referred to as Augmented Marauder in the provided content. The group is known for banking-trojan campaigns that heavily abuse WhatsApp as a primary infection and propagation vector, including self-propagating worm activity via WhatsApp Web. Reported campaigns target Brazilian users and, in separate email-based activity, Spanish-speaking users across Latin America and Spain. Across the cited reporting, Water Saci uses layered social-engineering-driven infection chains involving formats such as HTA, ZIP, PDF, VBS, MSI, and AutoIt components to deliver banking malware. The group has been observed evolving from PowerShell-based propagation to Python-based automation, with reporting noting possible use of AI tools or code-translation assistance. WhatsApp propagation has included automation through Selenium, WPPConnect, and hijacked authenticated WhatsApp Web sessions, with contact harvesting, mass messaging, personalized lures, and worm-like spread. One campaign also abused Microsoft Outlook accounts on infected hosts to send phishing emails from trusted accounts. The actor has been linked in reporting to delivery or operation of multiple banking malware families and variants, including Maverick, TCLBANKER, Casbaneiro variants, Astaroth, and activity described as structurally similar to Casbaneiro/Metamorfo. Trend Micro attributes the Maverick campaign to Water Saci, and reporting describes SORVEPOTEL as a WhatsApp-propagating worm associated with this activity. Elastic assessed TCLBANKER as a major evolution of the Maverick ecosystem associated with Trend Micro's Water Saci cluster. Trend Micro also reported possible links between Water Saci and developers of the Coyote banking trojan, but stated this is not definitive. Observed capabilities in the associated malware include Brazilian Portuguese locale checks, anti-analysis and anti-VM controls, debugger and security-tool detection, ETW disabling, hook removal, persistence via scheduled tasks and registry changes, process hollowing into svchost.exe, browser and window monitoring for banking and cryptocurrency targets, keylogging, screenshot and screen-stream capture, clipboard manipulation, remote command execution, file and process management, and fake banking overlays for credential theft. Targeting described in the content includes Brazilian banks and financial platforms, as well as payment and cryptocurrency services; separate BlueVoyant reporting says the group targeted Spanish-speaking users across Latin America and Spain with judicial-summons-themed phishing that ultimately delivered Casbaneiro.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Banks
  • Financial Services

Where they target

Geographies tied to known operations.

  • 🇧🇷 Brazil

Where they're from

Attributed origin per open-source reporting.

  • BR
MITRE ATT&CK

Tradecraft

23 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

10 of 15 tactics37 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0043
Reconnaissance
1 technique
T1598×2
Phishing for Information
TA0001
Initial Access
2 techniques
T1078
Valid Accounts
T1566×3
Phishing
T1566.001×4
Spearphishing Attachment
T1566.002
Spearphishing Link
T1566.003×2
Spearphishing via Service
TA0002
Execution
3 techniques
T1059
Command and Scripting Interpreter
T1059.001
PowerShell
T1059.005×2
Visual Basic
T1204
User Execution
T1204.001
Malicious Link
T1204.002×2
Malicious File
T1574
Hijack Execution Flow
T1574.001
DLL
TA0003
Persistence
1 technique
T1078
Valid Accounts
TA0004
Privilege Escalation
1 technique
T1078
Valid Accounts
TA0005
Stealth
5 techniques
T1036
Masquerading
T1078
Valid Accounts
T1218
System Binary Proxy Execution
T1218.005×2
Mshta
T1497
Virtualization/Sandbox Evasion
T1497.001
System Checks
T1574
Hijack Execution Flow
T1574.001
DLL
TA0006
Credential Access
1 technique
T1056
Input Capture
T1056.001
Keylogging
T1056.003
Web Portal Capture
TA0007
Discovery
1 technique
T1497
Virtualization/Sandbox Evasion
T1497.001
System Checks
TA0009
Collection
4 techniques
T1056
Input Capture
T1056.001
Keylogging
T1056.003
Web Portal Capture
T1114×2
Email Collection
T1114.001
Local Email Collection
T1185
Browser Session Hijacking
T1560
Archive Collected Data
TA0011
Command and Control
1 technique
T1105×2
Ingress Tool Transfer
IOCS

Observables

2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping23

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal5

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables2

Domains, IPs, and hashes tied to this actor, refreshed continuously.