Water Saci
Water Saci is a financially motivated cybercrime threat actor primarily active in Brazil. It is also referred to as Augmented Marauder in the provided content. The group is known for banking-trojan campaigns that heavily abuse WhatsApp as a primary infection and propagation vector, including self-propagating worm activity via WhatsApp Web. Reported campaigns target Brazilian users and, in separate email-based activity, Spanish-speaking users across Latin America and Spain. Across the cited reporting, Water Saci uses layered social-engineering-driven infection chains involving formats such as HTA, ZIP, PDF, VBS, MSI, and AutoIt components to deliver banking malware. The group has been observed evolving from PowerShell-based propagation to Python-based automation, with reporting noting possible use of AI tools or code-translation assistance. WhatsApp propagation has included automation through Selenium, WPPConnect, and hijacked authenticated WhatsApp Web sessions, with contact harvesting, mass messaging, personalized lures, and worm-like spread. One campaign also abused Microsoft Outlook accounts on infected hosts to send phishing emails from trusted accounts. The actor has been linked in reporting to delivery or operation of multiple banking malware families and variants, including Maverick, TCLBANKER, Casbaneiro variants, Astaroth, and activity described as structurally similar to Casbaneiro/Metamorfo. Trend Micro attributes the Maverick campaign to Water Saci, and reporting describes SORVEPOTEL as a WhatsApp-propagating worm associated with this activity. Elastic assessed TCLBANKER as a major evolution of the Maverick ecosystem associated with Trend Micro's Water Saci cluster. Trend Micro also reported possible links between Water Saci and developers of the Coyote banking trojan, but stated this is not definitive. Observed capabilities in the associated malware include Brazilian Portuguese locale checks, anti-analysis and anti-VM controls, debugger and security-tool detection, ETW disabling, hook removal, persistence via scheduled tasks and registry changes, process hollowing into svchost.exe, browser and window monitoring for banking and cryptocurrency targets, keylogging, screenshot and screen-stream capture, clipboard manipulation, remote command execution, file and process management, and fake banking overlays for credential theft. Targeting described in the content includes Brazilian banks and financial platforms, as well as payment and cryptocurrency services; separate BlueVoyant reporting says the group targeted Spanish-speaking users across Latin America and Spain with judicial-summons-themed phishing that ultimately delivered Casbaneiro.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Banks
- Financial Services
Where they target
Geographies tied to known operations.
- 🇧🇷 Brazil
Where they're from
Attributed origin per open-source reporting.
- BR
Tradecraft
23 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
5 malware families attributed to this actor across reporting.
Observables
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Threat cluster attributed with the Maverick banking trojan campaign, which is known to use the SORVEPOTEL worm to spread via WhatsApp Web to victims' contacts.
Financially motivated Brazilian cybercrime operation conducting banking-Trojan campaigns targeting Spanish-speaking users across Latin America and Spain via phishing emails and WhatsApp, using self-propagation to steal banking credentials.
Brazil-focused financially motivated actor evolving a multi-stage infection chain to spread a banking trojan via WhatsApp (including worm-like propagation), using layered file formats and shifting scripting languages to improve evasion and scale.
Brazil-focused financially motivated actor using WhatsApp worming and layered infection chains (HTA/PDF; Python variant) to deploy banking trojans and enable fraud (including RelayNFC mentioned in title).
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.