Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Water Saci

Also known as: tracked as, AISURU, REF3076

Description

Water Saci emerged as a sophisticated threat actor with a clear focus on financial theft in Latin America, especially Brazil. Its attack chain blends social engineering with advanced malware engineering—leveraging WhatsApp Web for initial delivery, then deploying self‑propagating modules that spread through contact lists and group chats via malicious ZIP and VBA scripts. The group’s flagship malware, SORVEPOTEL, is modular, supporting both WhatsApp hijacking payloads and a .NET infostealer component, and features UI overlays that closely mimic legitimate banking interfaces to harvest credentials. A notable technical signature of Water Saci is its AI‑driven conversion of PowerShell deployment scripts into obfuscated Python code, which enhances stealth and evasion across diverse execution environments. The malware also embeds an IMAP C&C routine with hardcoded credentials, enabling seamless updates from a predefined inbox such as terra.com.br, thereby increasing resilience against takedown efforts. Persistence is achieved through self‑propagating worm behavior and multi‑vector mechanisms, including scheduled tasks and registry persistence. Beyond banking trojans, the group has expanded its toolkit to include NFC relay attacks via PhantomCard and RelayNFC, allowing exfiltration of contactless payment data. Botnet operations tied to Kimwolf/AISURU compromise streaming devices, creating an additional foothold for lateral movement and command dissemination. These tactics illustrate a transition from traditional phishing emails to leveraging legitimate messaging platforms for large‑scale, automated attacks.

Goals & Targeting

Targeted Sectors

Financial services
Government
Healthcare
Defense
Education
Critical infrastructure
Energy
Information technology
Manufacturing
Telecommunications
Pharmaceutical
Food agriculture
Media

Targeted Countries / Regions

BR
MX
US
IL
CN
IN
PL
ES
IT

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 1 day ago

Executive Summary

Water Saci is a Brazil‑based cybercrime group that primarily targets financial institutions, using WhatsApp Web and AI‑enhanced phishing to deliver self‑propagating malware such as the SORVEPOTEL banking trojan. It employs multi‑format payloads (HTA, ZIP, PDF) alongside an embedded IMAP C&C routine for resilience, and additionally utilizes NFC relay weapons like PhantomCard/RelayNFC. The campaign shows large‑scale propagation through messaging platforms and botnet involvement via AISURU/Kimwolf to expand reach.

Goals & Targeting

Water Saci’s strategic objectives revolve around maximizing financial gain by targeting sectors with high-value personal and corporate data—financial services, banking, healthcare, government, telecom, and energy. The group focuses on Brazilian users but also extends to other Latin American and North American markets via language‑adapted phishing content (Portuguese/Spanish). By exploiting ubiquitous messaging apps like WhatsApp, the actor circumvents conventional email security controls while maintaining high social engineering efficacy. Its deployment of NFC relay malware reflects a drive to monetize contactless payment information, complementing credential theft from banking platforms.

Enhanced Description

Key Capabilities

  • Phishing via messaging apps (WhatsApp, SMS, Telegram)
  • Self‑propagating malware distribution through WhatsApp Web
  • AI‑driven phishing content creation
  • NFC card relay attacks (PhantomCard, RelayNFC)
  • Botnet operations using Kimwolf/AISURU to compromise streaming devices
  • Multi‑format attack chain (HTA, ZIP, PDF, PowerShell, Python, .NET scripts)
  • Script conversion from PowerShell to Python for obfuscation
  • Embedded IMAP C&C routine with hardcoded credentials
  • Persistent self‑propagating worm module
  • Anti‑analysis techniques in loader
  • Modular architecture delivering WhatsApp hijack and .NET infostealer components
  • Credential theft via UI overlay mimicking banking sites
  • Exploitation of legitimate browser profiles for evasion

MITRE ATT&CK Tactics

Initial Access
Execution
Command and Control
Persistence
Defense Evasion
Credential Access

ATT&CK Techniques

T1566.001
T1566.002
T1071.003
T1204.002
T1059.001
T1059.003
T1114

Software / Tooling

Ghost RAT
Havex RAT
PhantomCard
RelayNFC
Casbaneiro
Kimwolf
SORVEPOTEL
MAVERICK
TCLBANKER
.NET Reactor

Campaigns & Victims

Water Saci’s campaigns are highly automated and propagate rapidly through messaging platforms, especially WhatsApp Web. Their operational tempo is aggressive, with batches of new malicious ZIP files surfacing weekly to exploit the large social graph within Brazil and other Latin American countries. The actor frequently redeploys known malware families such as TCLBANKER and SORVEPOTEL but augments them with custom modules for WhatsApp hijacking and NFC relay capabilities. Known C&C infrastructure includes domains like terra.com.br and phishing back‑end services, while persistent updates are delivered via an IMAP routine that retrieves instructions from a dedicated inbox. Despite its sophistication, the actor’s targeting breadth—spanning finance, government, healthcare, and critical infrastructure—demonstrates opportunistic exploitation of any entity with exposed customer or payment data.

IOC Patterns

  • Phishing via WhatsApp and other messaging apps
  • Malicious links redirecting to fake login pages
  • Embedded malicious attachments in emails/SMS/WhatsApp messages
  • Self‑propagating malware delivered through WhatsApp Web
  • NFC relay attacks targeting banking cards
  • Malicious webpages impersonating legitimate applications
  • Hardcoded IMAP credentials used in the malware
  • Email extraction of C&C address via lines beginning with 'IP:' and subject title ‘meu’
  • Use of ZIP files for rapid propagation over WhatsApp
  • Domain-based C&C infrastructure linked to saogeraldoshiping.com
  • Malicious ZIP attachment (e.g., RES-20250930_112057.zip)
  • Use of legitimate browser profiles for stealth
  • UI overlay mimicking banking interfaces (credential harvesting)
  • Messaging platform hijacking (WhatsApp)

Recommended Actions

  • Implement employee security awareness training focused on phishing via messaging apps
  • Deploy email and SMS gateway filtering to block malicious attachments and links
  • Monitor for anomalous WhatsApp communications and enforce message verification procedures
  • Enable MFA on financial platforms and restrict NFC mobile payment usage where possible
  • Apply strong endpoint protection capable of detecting self‑propagating malware
  • Monitor and filter outbound messaging traffic, especially WhatsApp, for malicious attachments
  • Block or scrutinize IMAP connections to suspicious domains or credentials used by malware
  • Deploy threat intelligence feeds covering known domains like saogeraldoshiping.com and IPs from C&C updates
  • Enforce robust email filtering and attachment scanning to detect ZIP-based threats
  • Use EDR/AV solutions capable of detecting .NET Reactor obfuscation and script‑based attacks
  • Advise employees to avoid clicking unexpected attachments or links even from known contacts
  • Encourage use of secure, approved channels for business document transfers
  • Implement monitoring for suspicious WhatsApp-based activity and anomalous browser profile usage

Suggested Tags

Water Saci
WhatsApp phishing
NFC relay attack
PhantomCard
RelayNFC
Kimwolf botnet
AISURU
Casbaneiro
Ghost RAT
Havex RAT
Brazil financial sector target
AI‑enhanced phishing
Cybercrime
WhatsApp
Brazil
AI‑enhanced malware
Email‑based C&C
IMAP C&C
Multi‑vector persistence
Self‑propagating worm
Social engineering
SORVEPOTEL
TCLBANKER
Financial institutions
WhatsApp hijacking
Banking trojan
Spearphishing attachment
Malicious ZIP
.NET infostealer

Confidence Assessment

The available intelligence provides a solid view of Water Saci’s operations, especially around their messaging‑based delivery and NFC relay capabilities. However, gaps remain regarding precise attribution timing, full infrastructure mapping, and the extent of cross‑sector impact outside Brazil. Further monitoring of C&C domains (e.g., terra.com.br) and expansion of threat feeds will improve confidence.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. www.recordedfuture.com — Cited by web research for: AISURU
  2. www.elastic.co — Cited by web research for: REF3076
  3. www.trendmicro.com — Cited by web research for: MSI installer
  4. www.trendmicro.com — Cited by web research for: Donut
  5. https://www.elastic.co/security-labs/tclbanker-brazilian-trojan — Cited by AI analysis.

Intel Summary

7

Techniques

49

Tools

0

Campaigns

38

IOCs

0

Observed Data

4

Tactics

Tags

Financial Targeting
Critical Infrastructure
Backdoor / C2
APT
Banking Trojan
Social Engineering
Latin America
Email-Based Attack
Water Saci
WhatsApp phishing
NFC relay attack
PhantomCard
RelayNFC
Kimwolf botnet
AISURU
Casbaneiro
Ghost RAT
Havex RAT
Brazil financial sector target
AI‑enhanced phishing
Cybercrime
WhatsApp
Brazil
AI‑enhanced malware
Email‑based C&C
IMAP C&C
Multi‑vector persistence
Self‑propagating worm
Social engineering
SORVEPOTEL
TCLBANKER
Financial institutions
WhatsApp hijacking
Banking trojan
Spearphishing attachment
Malicious ZIP
.NET infostealer

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
B
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.