Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
phishing-campaign-intelligenceloader-delivery-mechanismgovernment-diplomatic-threateducation-sector-threat

Self-Propagating SORVEPOTEL Malware Spreads via WhatsApp Targeting Brazilian Windows Users

Updated 3mo agoFirst seen Oct 3, 20255 sources

A new malware campaign, identified as SORVEPOTEL, has been actively targeting Windows users in Brazil by exploiting the WhatsApp messaging platform as its primary infection vector. The campaign is engineered for rapid propagation rather than data theft or ransomware, focusing on widespread distribution through social engineering tactics. Attackers initiate the infection by sending convincing phishing messages from already compromised WhatsApp accounts, which increases the credibility of the malicious communication. These messages contain ZIP file attachments that masquerade as legitimate documents, such as receipts or health app files, and are specifically crafted to require opening on a desktop, indicating a focus on enterprise environments. Upon opening the ZIP file, victims are prompted to execute a Windows shortcut (LNK) file, which silently triggers the malware installation on the system. Once installed, SORVEPOTEL leverages active WhatsApp Web sessions to automatically send the same malicious ZIP file to all contacts and groups associated with the victim’s account, enabling rapid self-propagation. This automated spamming behavior often results in the infected WhatsApp accounts being banned due to excessive activity. Trend Micro telemetry indicates that out of 477 detected cases, 457 occurred in Brazil, highlighting a strong regional focus. The campaign has notably impacted government and public service organizations, but has also affected entities in manufacturing, technology, education, and construction sectors. While the primary goal appears to be mass distribution, there is concern that similar techniques have previously been used in Brazil to target financial data, raising the risk of future campaigns with more damaging objectives. Researchers have also observed that, in addition to WhatsApp, the attackers may use email as a secondary distribution channel, sending the same malicious ZIP files from seemingly legitimate email addresses. The use of social trust and automation in this campaign demonstrates a sophisticated approach to maximizing infection rates. There is currently no evidence that SORVEPOTEL exfiltrates data or encrypts files, but the potential for further exploitation remains. The campaign underscores the importance of user awareness regarding phishing tactics, especially those leveraging trusted communication platforms. Security teams are advised to monitor for suspicious WhatsApp Web activity and educate users about the risks of opening unsolicited attachments. The incident highlights the evolving threat landscape where messaging platforms are increasingly abused for malware propagation, particularly in regions with high platform adoption.

Share:
Self-Propagating SORVEPOTEL Malware Spreads via WhatsApp Targeting Brazilian Windows Users
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Oct 6, 20259mo ago

Trend Micro publishes defensive guidance for WhatsApp-based malware spread

Trend Micro advised organizations to disable WhatsApp auto-downloads, restrict file transfers through personal apps on managed devices, apply BYOD controls, and improve user awareness training against unexpected attachments. The company said it was continuing to monitor the campaign and recommended keeping defenses updated against messaging-platform attacks.

Additional analysis reveals banking and credential-theft capabilities

Follow-on reporting described Sorvepotel as capable of injecting shellcode into powershell_ise.exe, monitoring banking-related activity, and stealing browser credentials. The malware was also reported to conditionally act when victims visited targeted Brazilian financial institutions and cryptocurrency exchanges.

Oct 3, 20259mo ago

Trend Micro links campaign to Brazilian organizations across multiple sectors

Researchers reported that most observed infections were in Brazil and affected organizations in government, public services, manufacturing, technology, education, and construction. The campaign appeared aimed at enterprise users because it abused active WhatsApp Desktop/Web sessions to message all contacts and groups.

Researchers identify Sorvepotel infection chain and persistence methods

Trend Micro disclosed that the campaign delivers a ZIP archive containing a malicious LNK file that launches PowerShell to download additional payloads from attacker-controlled infrastructure such as typosquatted domains. The malware establishes persistence through the Windows Startup folder and communicates with command-and-control infrastructure.

Water Saci campaign begins using WhatsApp to spread malware in Brazil

A self-propagating malware campaign dubbed Water Saci began targeting Brazilian users by sending malicious ZIP attachments through compromised WhatsApp accounts and, in some cases, email. The operation focused on rapid spread across Windows systems, especially via WhatsApp Web/Desktop sessions.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

24 LINKEDOpen in app
Affected products
10 linked
WhatsappPowershellTelegramWindowsWhatsapp DesktopBraveInternet ExplorerFirefoxBraveTrend Vision One
Organizations
10 linked
Trend MicroMeta PlatformsMozillaMonte Sião Municipal GovernmentBrazilian governmentPIXMicrosoft CorporationGoogleTelegramWeTransfer
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.