Water SaciWater Saci

Also known as: Water Saci

Known aliases
1

Profile

Water Saci is a sophisticated cyber threat actor operating in Brazil, utilizing a multi-format attack chain that includes HTA files, ZIP archives, and PDFs to bypass security measures. The campaign employs an email-based C&C infrastructure using IMAP connections to terra.com.br accounts, enhancing its resilience and evasion tactics. It leverages social engineering through WhatsApp to propagate malware, specifically the SORVEPOTEL banking trojan, and incorporates advanced techniques for infection and persistence. The modular architecture of the malware allows for dynamic adaptation and extraction of sensitive credentials, indicating a significant evolution in adversarial capabilities.

Aliases· 1

Water Saci

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
Water Curupira
Actor
Water Makara
Actor
SHADOW-WATER-063
Actor
Water Labbu
Actor
Water Orthrus
Actor
DangerousSavanna
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.