Threat hunters have identified similarities between Coyote, a banking malware, and Maverick, a newly revealed malicious program spread through WhatsApp.
As stated in a report by CyberProof, the two strains of malware are developed using .NET, aimed at Brazilian users and financial institutions, and possess the same functions for decryption, targeting banking URLs and observing banking apps. Of greater significance, both can disseminate via WhatsApp Web.
Trend Micro documented Maverick for the first time in early last month, linking it to a threat actor named Water Saci. The campaign consists of two elements: An autonomous malware known as SORVEPOTEL that disseminates through the desktop web version of WhatsApp and is utilized to send a ZIP file with the Maverick payload.
The malicious software is intended to keep an eye on active browser window tabs for URLs that correspond to a fixed list of financial institutions in Latin America read more about WhatsApp Malware ‘Maverick’ Hijacks Browser Sessions to Target Brazil’s Biggest Banks.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
