SYMBOLCOMMON_NAMEaka. SYNONYMS

Water Saci  (Back to overview)


Water Saci is a sophisticated cyber threat actor operating in Brazil, utilizing a multi-format attack chain that includes HTA files, ZIP archives, and PDFs to bypass security measures. The campaign employs an email-based C&C infrastructure using IMAP connections to terra.com.br accounts, enhancing its resilience and evasion tactics. It leverages social engineering through WhatsApp to propagate malware, specifically the SORVEPOTEL banking trojan, and incorporates advanced techniques for infection and persistence. The modular architecture of the malware allows for dynamic adaptation and extraction of sensitive credentials, indicating a significant evolution in adversarial capabilities.


Associated Families

There are currently no families associated with this actor.


References
2025-12-02Trend MicroByron Gelera, Emmanuel Panopio, Ian Kenefick, Jeffrey Francis Bonaobra, Joe Soares, Sarah Pearl Camiling
Unraveling Water Saci's New Multi-Format, AI-Enhanced Attacks Propagated via WhatsApp
Water Saci
2025-10-27Trend MicroEmmanuel Panopio, Jeffrey Francis Bonaobra, Joe Soares
Active Water Saci Campaign Spreading Via WhatsApp Features Multi-Vector Persistence and Sophisticated C&C
Water Saci

Credits: MISP Project