Brazil Hit by Banking Trojan Spread via WhatsApp Worm and RelayNFC NFC Relay Fraud

The Water Saci threat actor is using a sophisticated, multi-layered infection chain via WhatsApp to spread a banking trojan in Brazil, utilizing HTA files and PDFs. Concurrently, a new Android malware called RelayNFC is targeting Brazilian users with NFC relay attacks to steal contactless payment data.

Edward Kiledjian @ekiledjian