WhatsApp faces wave of cyberattacks: Accounts turning into zombies

WhatsApp Web users are under serious threat due to malware dubbed the 'Brazil Virus.' Experts warn users to be particularly cautious of suspicious files.

12punto

WhatsApp, one of the world's most widely used instant messaging platforms, has recently become the target of a new cyberattack campaign. In this attack, malware named "SORVEPOTEL" is spreading primarily through files with the ".zip" extension, often labeled as "photo.zip." Cybercriminals exploit users' social connections by sending messages that appear to come from someone they know, using curiosity to trick them into opening the malicious file.

The new threat specifically targets hijacking WhatsApp Web sessions on computers running the Windows operating system. Experts point out that the messages sent often feature attention-grabbing content such as "Is this you in this photo?"

ACCOUNTS TURNING INTO ZOMBIES

As soon as the malicious file is downloaded and opened on a computer, the malware running in the background completely takes over the WhatsApp Web session within seconds. The compromised account automatically sends similar trap messages to the user's entire contact list, accelerating the spread. This triggers a chain reaction that can infect hundreds of accounts in a very short time.

Experts report that some versions of such software not only hijack messaging accounts but can also access and steal critical data on the computer, and even remotely control the system.

WHAT PRECAUTIONS SHOULD BE TAKEN?

IT security experts list the fundamental precautions that should be taken to ensure WhatsApp and general digital security as follows:

  • Check the "Linked Devices" section of WhatsApp at regular intervals and immediately terminate any sessions you do not recognize.
  • Be particularly cautious about unexpected files with ZIP, LNK, or EXE extensions. Never open a file unless you are certain of its source.
  • Protect your account with an additional layer of security by enabling the two-step verification feature.
  • Take unusual situations, such as "PowerShell" or "Command Prompt" windows opening on your computer without your permission, seriously; this may be an indication that your system has been compromised.

EXPERTS WARN: THE GREATEST RISK IS IN THE ATTACHED FILE

Consultants working in the security field emphasize that while it is unlikely for users to be at risk just by reading messages, the real danger begins when the attached file is opened. Experts specifically warn that "the reason for the rapid spread is the use of familiar profiles," highlighting the importance of digital hygiene.

Users are advised to be more careful than ever regarding the content and attachments of incoming messages and to exercise common sense when opening files, regardless of who they come from. In this way, personal data can be protected, and the account can be prevented from falling into the hands of others.