Water Saci

Origin
BR
Primary motivation
financial-gain
Sophistication
advanced
Resource level
organization
Actor type
criminal
Profile updated
2026-07-07 12:22:29

Targeted industries: financial-services

Targeted regions: country_code:br

Context

Water Saci is a sophisticated cyber threat actor operating in Brazil, utilizing a multi-format attack chain that includes HTA files, ZIP archives, and PDFs to bypass security measures. The campaign employs an email-based C&C infrastructure using IMAP connections to terra.com.br accounts, enhancing its resilience and evasion tactics. It leverages social engineering through WhatsApp to propagate malware, specifically the SORVEPOTEL banking trojan, and incorporates advanced techniques for infection and persistence. The modular architecture of the malware allows for dynamic adaptation and extraction of sensitive credentials, indicating a significant evolution in adversarial capabilities.

Reports & references

  • Trend Micro — Active Water Saci Campaign Whatsapp Update (report)
  • Trend Micro — Water Saci (report)

External references