Also known as: tracked as, AISURU, REF3076
Water Saci emerged as a sophisticated threat actor with a clear focus on financial theft in Latin America, especially Brazil. Its attack chain blends social engineering with advanced malware engineering—leveraging WhatsApp Web for initial delivery, then deploying self‑propagating modules that spread through contact lists and group chats via malicious ZIP and VBA scripts. The group’s flagship malware, SORVEPOTEL, is modular, supporting both WhatsApp hijacking payloads and a .NET infostealer component, and features UI overlays that closely mimic legitimate banking interfaces to harvest credentials. A notable technical signature of Water Saci is its AI‑driven conversion of PowerShell deployment scripts into obfuscated Python code, which enhances stealth and evasion across diverse execution environments. The malware also embeds an IMAP C&C routine with hardcoded credentials, enabling seamless updates from a predefined inbox such as terra.com.br, thereby increasing resilience against takedown efforts. Persistence is achieved through self‑propagating worm behavior and multi‑vector mechanisms, including scheduled tasks and registry persistence. Beyond banking trojans, the group has expanded its toolkit to include NFC relay attacks via PhantomCard and RelayNFC, allowing exfiltration of contactless payment data. Botnet operations tied to Kimwolf/AISURU compromise streaming devices, creating an additional foothold for lateral movement and command dissemination. These tactics illustrate a transition from traditional phishing emails to leveraging legitimate messaging platforms for large‑scale, automated attacks.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Water Saci is a Brazil‑based cybercrime group that primarily targets financial institutions, using WhatsApp Web and AI‑enhanced phishing to deliver self‑propagating malware such as the SORVEPOTEL banking trojan. It employs multi‑format payloads (HTA, ZIP, PDF) alongside an embedded IMAP C&C routine for resilience, and additionally utilizes NFC relay weapons like PhantomCard/RelayNFC. The campaign shows large‑scale propagation through messaging platforms and botnet involvement via AISURU/Kimwolf to expand reach.
Goals & Targeting
Water Saci’s strategic objectives revolve around maximizing financial gain by targeting sectors with high-value personal and corporate data—financial services, banking, healthcare, government, telecom, and energy. The group focuses on Brazilian users but also extends to other Latin American and North American markets via language‑adapted phishing content (Portuguese/Spanish). By exploiting ubiquitous messaging apps like WhatsApp, the actor circumvents conventional email security controls while maintaining high social engineering efficacy. Its deployment of NFC relay malware reflects a drive to monetize contactless payment information, complementing credential theft from banking platforms.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Water Saci’s campaigns are highly automated and propagate rapidly through messaging platforms, especially WhatsApp Web. Their operational tempo is aggressive, with batches of new malicious ZIP files surfacing weekly to exploit the large social graph within Brazil and other Latin American countries. The actor frequently redeploys known malware families such as TCLBANKER and SORVEPOTEL but augments them with custom modules for WhatsApp hijacking and NFC relay capabilities. Known C&C infrastructure includes domains like terra.com.br and phishing back‑end services, while persistent updates are delivered via an IMAP routine that retrieves instructions from a dedicated inbox. Despite its sophistication, the actor’s targeting breadth—spanning finance, government, healthcare, and critical infrastructure—demonstrates opportunistic exploitation of any entity with exposed customer or payment data.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The available intelligence provides a solid view of Water Saci’s operations, especially around their messaging‑based delivery and NFC relay capabilities. However, gaps remain regarding precise attribution timing, full infrastructure mapping, and the extent of cross‑sector impact outside Brazil. Further monitoring of C&C domains (e.g., terra.com.br) and expansion of threat feeds will improve confidence.
No campaigns linked yet.
No observed data linked yet.
7
Techniques
49
Tools
0
Campaigns
38
IOCs
0
Observed Data
4
Tactics