Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
financial-sector-threatcredential-stealer-activityphishing-campaign-intelligencedefense-evasion-method

Maverick Banking Trojan Spreads via WhatsApp and Steals Financial Credentials

Updated 3mo agoFirst seen Oct 17, 20252 sources

A new banking Trojan named Maverick has been identified targeting users in Brazil through a sophisticated, fileless malware campaign. The infection chain begins with the distribution of malicious ZIP files containing LNK shortcuts, which are sent via WhatsApp messages. These LNK files are not blocked by WhatsApp, allowing the malware to propagate widely among Brazilian users. Once a device is infected, the Maverick Trojan leverages the open-source WPPConnect project to automate the sending of further malicious messages from the victim’s WhatsApp Web account, effectively turning compromised devices into worms that spread the malware to additional contacts. The Trojan is highly targeted, checking the infected system’s time zone, language, and regional settings to ensure it only installs on Brazilian machines. Upon successful infection, Maverick operates entirely in memory, minimizing disk activity and making detection more difficult. The malware is modular, using PowerShell and .NET components to execute its payloads. Its primary objective is to steal banking and UPI credentials by monitoring browser activity, taking screenshots, logging keystrokes, and overlaying phishing pages when users access banking websites. Maverick can also control the mouse, block the screen during sensitive operations, and terminate processes to evade detection. The campaign specifically targets 26 Brazilian banks, 6 cryptocurrency exchanges, and a major payment platform, indicating a broad financial focus. The command-and-control infrastructure is designed to verify that downloads originate from the malware itself, adding another layer of evasion. Researchers have noted significant code overlap between Maverick and the previously known Coyote Trojan, but Maverick is considered a distinct and new threat. The use of WhatsApp as a distribution vector is particularly concerning, as it exploits the trust between contacts and the widespread use of the messaging platform in Brazil. The fileless nature of the attack chain, combined with the use of legitimate open-source tools, complicates detection and remediation efforts. Security experts recommend heightened vigilance for suspicious WhatsApp messages containing attachments, especially those in Portuguese or referencing financial matters. Organizations and individuals are urged to update their security solutions and educate users about the risks of opening unsolicited files, even from known contacts. The emergence of Maverick underscores the evolving tactics of cybercriminals targeting the Brazilian financial sector and highlights the need for robust, multi-layered defenses.

Share:
Maverick Banking Trojan Spreads via WhatsApp and Steals Financial Credentials
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Oct 15, 20258mo ago

Researchers publicly disclose Maverick as a distinct new banking threat

Securelist published technical analysis identifying Maverick as a new Brazilian banking trojan, noting code and technique overlap with Coyote but assessing it as a separate threat. The report detailed its banking credential theft, overlays, keylogging, screenshots, and remote-control capabilities.

Oct 10, 20259mo ago

Kaspersky records 62,000 Maverick infection attempts in early October

Kaspersky reported blocking about 62,000 infection attempts in Brazil during the first 10 days of October. The company detected the activity as HEUR:Trojan.Multi.Powenot.a and HEUR:Trojan-Banker.MSIL.Maverick.gen.

Oct 1, 20259mo ago

Maverick uses hijacked WhatsApp accounts to self-propagate

The malware incorporated a WhatsApp account hijacking and spam module using WPPConnect and Selenium to automate WhatsApp Web and send malicious messages to victims' contacts. This added worm-like propagation to the banking trojan campaign.

Maverick banking trojan campaign begins large-scale spread in Brazil

A new Brazilian banking trojan dubbed Maverick was distributed at scale through WhatsApp messages carrying ZIP archives with malicious Windows LNK files. The campaign used a modular, largely fileless infection chain with PowerShell, in-memory .NET loading, and geofencing to restrict infections to Brazil.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

13 LINKEDOpen in app
Malware
2 linked
Affected products
9 linked
WhatsappNetPowershellBraveInternet ExplorerFirefoxBraveNetChrome
Organizations
2 linked
KasperskyMeta Platforms
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Maverick Banking Trojan Spreads via WhatsApp and Steals Financial Credentials | Mallory