Episode
Stealer in the status bar.
- Podcast
- Research Saturday
- Published
- Feb 14, 2026
- Duration seconds
- 934
- Processing state
not_requested- Canonical source
- https://thecyberwire.com/podcasts/research-saturday/412/notes
Actions
POST https://stenobird.com/v1/public/podcasts/research-saturday-1377435/episodes/stealer-in-the-status-bar/transcription-requests
Idempotently request low-priority transcript generation for this episode.GET https://stenobird.com/podcast/research-saturday-1377435/stealer-in-the-status-bar.md
Read the agent-friendly Markdown representation of this episode resource.
Summary
Today we have Ziv Mador, VP of Security Research from LevelBlue SpiderLabs discussing their work on "SpiderLabs IDs New Banking Trojan Distributed Through WhatsApp." Researchers at LevelBlue SpiderLabs have identified a new Brazilian banking Trojan dubbed Eternidade Stealer, spread through WhatsApp hijacking and social engineering campaigns that use a Python-based worm to steal contacts and distribute malicious MSI installers. The Delphi-compiled malware targets Brazilian victims, profiles infected systems, dynamically retrieves its command-and-control server via IMAP email, and deploys banking overlays to harvest credentials from financial institutions and cryptocurrency platforms. The campaign reflects the continued evolution of Brazil’s cybercrime ecosystem, combining WhatsApp propagation, geofencing, encrypted C2 communications, and process injection to maintain stealth and persistence. The research can be found here: SpiderLabs IDs New Banking Trojan Distributed Through WhatsApp