# Stealer in the status bar. Page: https://stenobird.com/podcast/research-saturday-1377435/stealer-in-the-status-bar Text version: https://stenobird.com/podcast/research-saturday-1377435/stealer-in-the-status-bar.md Podcast: [Research Saturday](https://stenobird.com/podcast/research-saturday-1377435) Published: 2026-02-14T06:00:00+00:00 Episode link: https://thecyberwire.com/podcasts/research-saturday/412/notes Audio file: https://pdst.fm/e/pdrl.fm/6ec23a/traffic.megaphone.fm/CYBW3731424921.mp3?updated=1770998742 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/research-saturday-1377435/episodes/stealer-in-the-status-bar Duration seconds: 934 ## Resource Today we have Ziv Mador, VP of Security Research from LevelBlue SpiderLabs discussing their work on "SpiderLabs IDs New Banking Trojan Distributed Through WhatsApp." Researchers at LevelBlue SpiderLabs have identified a new Brazilian banking Trojan dubbed Eternidade Stealer, spread through WhatsApp hijacking and social engineering campaigns that use a Python-based worm to steal contacts and distribute malicious MSI installers. The Delphi-compiled malware targets Brazilian victims, profiles infected systems, dynamically retrieves its command-and-control server via IMAP email, and deploys banking overlays to harvest credentials from financial institutions and cryptocurrency platforms. The campaign reflects the continued evolution of Brazil’s cybercrime ecosystem, combining WhatsApp propagation, geofencing, encrypted C2 communications, and process injection to maintain stealth and persistence. The research can be found here: SpiderLabs IDs New Banking Trojan Distributed Through WhatsApp ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/research-saturday-1377435/episodes/stealer-in-the-status-bar/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/research-saturday-1377435/stealer-in-the-status-bar.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.