Self-Propagating SORVEPOTEL Malware Spreads via WhatsApp Targeting Brazilian Windows Users
A new malware campaign, identified as SORVEPOTEL, has been actively targeting Windows users in Brazil by exploiting the WhatsApp messaging platform as its primary infection vector. The campaign is engineered for rapid propagation rather than data theft or ransomware, focusing on widespread distribution through social engineering tactics. Attackers initiate the infection by sending convincing phishing messages from already compromised WhatsApp accounts, which increases the credibility of the malicious communication. These messages contain ZIP file attachments that masquerade as legitimate documents, such as receipts or health app files, and are specifically crafted to require opening on a desktop, indicating a focus on enterprise environments. Upon opening the ZIP file, victims are prompted to execute a Windows shortcut (LNK) file, which silently triggers the malware installation on the system. Once installed, SORVEPOTEL leverages active WhatsApp Web sessions to automatically send the same malicious ZIP file to all contacts and groups associated with the victim’s account, enabling rapid self-propagation. This automated spamming behavior often results in the infected WhatsApp accounts being banned due to excessive activity. Trend Micro telemetry indicates that out of 477 detected cases, 457 occurred in Brazil, highlighting a strong regional focus. The campaign has notably impacted government and public service organizations, but has also affected entities in manufacturing, technology, education, and construction sectors. While the primary goal appears to be mass distribution, there is concern that similar techniques have previously been used in Brazil to target financial data, raising the risk of future campaigns with more damaging objectives. Researchers have also observed that, in addition to WhatsApp, the attackers may use email as a secondary distribution channel, sending the same malicious ZIP files from seemingly legitimate email addresses. The use of social trust and automation in this campaign demonstrates a sophisticated approach to maximizing infection rates. There is currently no evidence that SORVEPOTEL exfiltrates data or encrypts files, but the potential for further exploitation remains. The campaign underscores the importance of user awareness regarding phishing tactics, especially those leveraging trusted communication platforms. Security teams are advised to monitor for suspicious WhatsApp Web activity and educate users about the risks of opening unsolicited attachments. The incident highlights the evolving threat landscape where messaging platforms are increasingly abused for malware propagation, particularly in regions with high platform adoption.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
5 events from the most recent confirmed update back to the earliest known activity.
Trend Micro publishes defensive guidance for WhatsApp-based malware spread
Trend Micro advised organizations to disable WhatsApp auto-downloads, restrict file transfers through personal apps on managed devices, apply BYOD controls, and improve user awareness training against unexpected attachments. The company said it was continuing to monitor the campaign and recommended keeping defenses updated against messaging-platform attacks.
Additional analysis reveals banking and credential-theft capabilities
Follow-on reporting described Sorvepotel as capable of injecting shellcode into powershell_ise.exe, monitoring banking-related activity, and stealing browser credentials. The malware was also reported to conditionally act when victims visited targeted Brazilian financial institutions and cryptocurrency exchanges.
Trend Micro links campaign to Brazilian organizations across multiple sectors
Researchers reported that most observed infections were in Brazil and affected organizations in government, public services, manufacturing, technology, education, and construction. The campaign appeared aimed at enterprise users because it abused active WhatsApp Desktop/Web sessions to message all contacts and groups.
Researchers identify Sorvepotel infection chain and persistence methods
Trend Micro disclosed that the campaign delivers a ZIP archive containing a malicious LNK file that launches PowerShell to download additional payloads from attacker-controlled infrastructure such as typosquatted domains. The malware establishes persistence through the Windows Startup folder and communicates with command-and-control infrastructure.
Water Saci campaign begins using WhatsApp to spread malware in Brazil
A self-propagating malware campaign dubbed Water Saci began targeting Brazilian users by sending malicious ZIP attachments through compromised WhatsApp accounts and, in some cases, email. The operation focused on rapid spread across Windows systems, especially via WhatsApp Web/Desktop sessions.
Related entities
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Sources
5 references tracked. Mallory keeps watching after this page renders.
WhatsApp Worm: New SORVEPOTEL Malware Hijacks Sessions to Spread Aggressively Across Brazil
securityonline.info
Open sourceSelf-Propagating Malware Hits WhatsApp Users in Brazil
darkreading.com
Open sourceNew malware leverages WhatsApp to target Brazilian government and businesses
therecord.media
Open sourceSelf-Propagating Malware Spreading Via WhatsApp, Targets Brazilian Users | Trend Micro (US)
trendmicro.com
Open sourceResearchers Warn of Self-Spreading WhatsApp Malware Named SORVEPOTEL
thehackernews.com
Open sourceSee the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


