SORVEPOTEL is a self-propagating Windows worm associated with the Water Saci campaign, active primarily in Brazil since September 2025. It abuses authenticated WhatsApp Web sessions to distribute malicious attachments through compromised users’ accounts. Affected organizations include government and public services, manufacturing, technology, education, and construction.
Infection typically begins with Portuguese-language phishing messages from compromised contacts or phishing emails carrying malicious archives. Observed execution chains use Windows shortcuts, Visual Basic scripts, HTML applications, and PowerShell. The propagation component uses Selenium, ChromeDriver, and WhatsApp automation libraries to control browser sessions. It copies browser profile data, including cookies and authentication tokens, to reuse existing WhatsApp authentication without a new QR-code scan. It harvests contacts, sends personalized lure messages and malicious attachments, and reports contact data and delivery results to attacker infrastructure. Operators can remotely pause and resume propagation. Implementations have evolved from .NET and PowerShell components to Python variants with broader browser support.
Script-based variants include a backdoor supporting reconnaissance, command execution, screenshots, process management, and file operations. They establish persistence through registry modifications and scheduled tasks, perform language and analysis-tool checks, and retrieve command-and-control locations through IMAP before polling HTTP servers for commands.
SORVEPOTEL also serves as a distribution conduit for banking malware, including Maverick, whose payloads monitor financial websites and capture credentials through deceptive banking interfaces. These downstream banking capabilities are distinct from the worm’s propagation functionality and are not present in every variant.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
As observed in our previously published research on the SORVEPOTEL malware and the broader Water Saci campaign, this popular platform has been used to launch sophisticated campaigns.
35 distinct techniques documented for this family, organized by ATT&CK tactic.
SORVEPOTEL has been observed to spread across Windows systems through convincing phishing messages with malicious ZIP file attachments.
When the LNK file is executed, this shortcut covertly launches a command-line or PowerShell script that downloads the primary malware payload from attacker-controlled domains.
The decrypted command retrieves a malicious script from a specified URL and executes it in memory using the Invoke-Expression (IEX) function.
The script drops a .bat script which downloads and installs Python.zip, ChromeDriver.exe and PIP
It starts with a Phishing email with a ZIP archived malicious VBS script file.
This variant uses a Python script for malware distribution along with a Banking Trojan.
The Selenium Chrome driver is used to inject a malicious JS code in WhatsApp Web.
the .NET DLL decrypts and subsequently injects into separate instances of suspended powershell_ise.exe processes it creates
the .NET DLL decrypts and subsequently injects into separate instances of suspended powershell_ise.exe processes it creates
It runs in hidden mode (- w hidden ) to evade user notice and leverages the encoded command (- enc ) feature for additional payload obfuscation.
The message has a ZIP archive attachment, bearing the name "RES-20250930_112057.zip,” or "ORCAMENTO_114418.zip," or something similarly disguised as a benign document, such as a receipt, budget, or health app-related file.
the .NET DLL decrypts and subsequently injects into separate instances of suspended powershell_ise.exe processes it creates
the .NET DLL decrypts and subsequently injects into separate instances of suspended powershell_ise.exe processes it creates
it implements anti-analysis measures by scanning for specific process names commonly associated with debugging or reverse engineering tools. If any of the following processes are detected, the DLL will terminate itself to evade analysis.
AutoIt Script contains an infinite loop that monitors the active windows and decides when to execute the malicious payload by scanning all visible window title strings
If it still finds nothing, It looks for program display names that contain keywords of AV program names in the Windows “Uninstall” registry keys.
System information like Computer name, OS info, Username, Local IP, External IP, Current Timestamp, AntiVirus Products, Windows Edition/Version, Processor Name, Total RAM, Logon Domain
It then looks for common security apps used by Brazilian banks by checking if certain folders exist on the C: drive
it implements anti-analysis measures by scanning for specific process names commonly associated with debugging or reverse engineering tools. If any of the following processes are detected, the DLL will terminate itself to evade analysis.
System information like Computer name, OS info, Username, Local IP, External IP, Current Timestamp, AntiVirus Products, Windows Edition/Version, Processor Name, Total RAM, Logon Domain, Brazilian banking sites visited are sent to the attacker’s server.
it establishes a C&C communication channel ... and subsequently instantiates a WatsonClient that connects to the malicious server " adoblesecuryt[.]com " over port 443 (HTTPS).
it establishes a C&C communication channel ... and subsequently instantiates a WatsonClient that connects to the malicious server " adoblesecuryt[.]com " over port 443 (HTTPS).
33 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
22 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A banking trojan previously linked to WhatsApp-delivered campaigns in Brazil and referenced as prior related research context for the current Water Saci activity.
A Windows malware family used in the Water Saci campaign that spreads via phishing ZIP/LNK attachments and then propagates through hijacked WhatsApp Web sessions. It establishes persistence, downloads staged PowerShell and .NET payloads, monitors banking-related activity, targets Brazilian financial institutions, steals information and credentials through overlay phishing, and supports remote backdoor commands.
Older malware family referenced as a predecessor or related family to TCLBANKER.
Worm used to spread Maverick-like banking trojan activity via WhatsApp Web by hijacking authenticated sessions and sending messages to contacts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.