{"id":133859,"date":"2025-11-20T13:05:21","date_gmt":"2025-11-20T13:05:21","guid":{"rendered":"https:\/\/cybersecuritynews.com\/?p=133859"},"modified":"2025-11-20T13:05:21","modified_gmt":"2025-11-20T13:05:21","slug":"new-malware-via-whatsapp-exfiltrate-contacts","status":"publish","type":"post","link":"https:\/\/cybersecuritynews.com\/new-malware-via-whatsapp-exfiltrate-contacts\/","title":{"rendered":"New Malware Via WhatsApp Exfiltrate Contacts to Attack Server and Deploys Malware"},"content":{"rendered":"\n<p>Trustwave SpiderLabs researchers have identified a sophisticated banking trojan called Eternidade Stealer that spreads through WhatsApp hijacking and social engineering tactics.<\/p>\n\n\n\n<p>The malware, written in Delphi, represents a significant evolution in Brazil&#8217;s cybercriminal landscape, combining advanced contact harvesting with credential theft targeting financial institutions.<\/p>\n\n\n\n<p>The threat emerges from a multi-stage infection chain that begins with an obfuscated VBScript sent via WhatsApp messages.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjiaXZ5WhI3IO_ruRJAVXJaGaw2qHNvzjRGKL2-zt01wBXz6wGOEh4LQr2cdA5wgrEzqsDha2l_xwA5LtCKmt7jgFcUVSYzYUn9D6s-NWNsy3Gx6ScjT1vZpxar5pqAntQX1wwRddEZ9pNylzzdoBLNiCIUhYNM1rdLt_0DOWESjaBHrgxP_4qFzem9ENU\/s16000\/The%20message%20received%20via%20WhatsApp%20during%20the%20preparation%20of%20the%20current%20report%20(Source%20-%20Trustwave).webp\" alt=\"The message received via WhatsApp during the preparation of the current report (Source - Trustwave)\" \/><figcaption class=\"wp-element-caption\">The message received via WhatsApp during the preparation of the current report (Source &#8211; Trustwave)<\/figcaption><\/figure><\/div>\n\n\n<p>When executed, the script downloads a batch file containing two primary payloads: a Python-based WhatsApp worm and an MSI installer that deploys the <a href=\"https:\/\/cybersecuritynews.com\/android-banking-trojan-google-play-mimic\/\" target=\"_blank\" rel=\"noreferrer noopener\">banking trojan<\/a>.<\/p>\n\n\n\n<p>This distribution method exploits the messaging platform&#8217;s trusted nature, making users more likely to interact with malicious attachments shared by contacts whose accounts have been compromised.<\/p>\n\n\n\n<p>Trustwave security analysts <a href=\"https:\/\/www.trustwave.com\/en-us\/resources\/blogs\/spiderlabs-blog\/spiderlabs-ids-new-banking-trojan-distributed-through-whatsapp\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">noted<\/a> that the malware demonstrates remarkable sophistication in targeting Brazilian victims specifically.<\/p>\n\n\n\n<p>The trojan uses geolocation checks to verify the operating system language is Brazilian Portuguese before proceeding with infection.<\/p>\n\n\n\n<p>If the system language doesn&#8217;t match, the malware displays an error message and terminates, preventing accidental infections outside its intended target region and avoiding sandbox detection.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-the-contact-harvesting-mechanism\"><strong>The Contact Harvesting Mechanism<\/strong><\/h2>\n\n\n\n<p>The core functionality of Eternidade Stealer involves stealing entire WhatsApp contact lists through the <code>obter_contatos()<\/code> function, which executes JavaScript code using the WPP.contact.list() API.<\/p>\n\n\n\n<p>The <a href=\"https:\/\/cybersecuritynews.com\/chatgpt-powered-malware-analysis\/\" target=\"_blank\" rel=\"noreferrer noopener\">malware<\/a> intelligently filters out groups, business contacts, and broadcast lists, focusing specifically on individual personal contacts more likely to fall victim to phishing messages.<\/p>\n\n\n\n<p>Each stolen contact record includes the full WhatsApp ID, contact name, phone number, and whether the contact is saved.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjSeU0WL8F2dJUWTtyFAoi21NsVsb-hQkBl-kfhwvjEPEOODt2YPVd296wylJlpPPYNDwTqx6B45IPCc0yNzJU7cvauNOqzkA80nGg54MHmAacXBdxzV7roITj4FEcDPM9NhQLl9fn_E3VZqlkQWgydGsdX4FRYtStztfp4CijRiNUHR3yzzEiTUh5uUeU\/s16000\/Eternidade%20Stealer%E2%80%99s%20attack%20chain%20(Source%20-%20Trustwave).webp\" alt=\"Eternidade Stealer\u2019s attack chain (Source - Trustwave)\" \/><figcaption class=\"wp-element-caption\">Eternidade Stealer\u2019s attack chain (Source &#8211; Trustwave)<\/figcaption><\/figure><\/div>\n\n\n<p>After collection, the malware immediately sends this data to the command-and-control server via HTTP POST requests without user interaction.<\/p>\n\n\n\n<p>What makes Eternidade Stealer particularly dangerous is its dual-layer persistence mechanism. The trojan uses hardcoded credentials to connect via IMAP to an email account controlled by threat actors.<\/p>\n\n\n\n<p>It extracts the command-and-control server address from email subjects and bodies, allowing attackers to update their infrastructure dynamically and maintain connections even if specific <a href=\"https:\/\/cybersecuritynews.com\/pypi-to-block-domains-resurrection-attacks\/\" target=\"_blank\" rel=\"noreferrer noopener\">domains<\/a> are seized.<\/p>\n\n\n\n<p>The malware targets over 40 Brazilian financial institutions, payment services like MercadoPago, and cryptocurrency exchanges, including Binance and Coinbase.<\/p>\n\n\n\n<p>When a victim accesses a targeted banking application, the trojan activates its overlay capability, displaying fake login screens designed to steal credentials seamlessly.<\/p>\n\n\n\n<p>System reconnaissance capabilities collect information, including OS details, installed antivirus software, public and local IP addresses, and running processes.<\/p>\n\n\n\n<p>This reconnaissance helps threat actors determine whether to proceed with <a href=\"https:\/\/cybersecuritynews.com\/credential-theft-risks\/\" target=\"_blank\" rel=\"noreferrer noopener\">credential theft<\/a> or banking overlay deployment.<\/p>\n\n\n\n<p>The investigation revealed that one threat actor&#8217;s infrastructure recorded 454 connection attempts globally, with significant traffic from the United States and European countries, suggesting broader attack ambitions beyond Brazil&#8217;s borders.<\/p>\n\n\n\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 92%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Trustwave SpiderLabs researchers have identified a sophisticated banking trojan called Eternidade Stealer that spreads through WhatsApp hijacking and social engineering tactics. The malware, written in Delphi, represents a significant evolution in Brazil&#8217;s cybercriminal landscape, combining advanced contact harvesting with credential theft targeting financial institutions. The threat emerges from a multi-stage infection chain that begins with [&hellip;]<\/p>\n","protected":false},"author":6,"featured_media":133886,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjsRczYujxkV0dhyphenhyphentP3hITzlL90I8lTiPsubr3hcgAEMmXOyR3brX8RGlW6yxAXuVeoP4a6FlEmeKa0TpEkUOFRLJZPUuER4nmGs3BnrTykPUMy9TMnZQnofuBWhabnXt0XTusHv86ITvWrxRCDhzguO3zbtsjtVRYyPdq1JequbuJfgdItRLqlXL3Kbq4\/s16000\/New%20Malware%20Via%20WhatsApp%20Exfiltrate%20Contacts%20to%20Attack%20Server%20and%20Deploys%20Malware.webp","fifu_image_alt":"","_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[11,48],"tags":[149,151],"class_list":{"0":"post-133859","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-cyber-security-news","8":"category-threats","9":"tag-cyber-security","10":"tag-cyber-security-news"},"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v25.7.1 (Yoast SEO v25.7) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>New Malware Via WhatsApp Exfiltrate Contacts to Attack Server and Deploys Malware<\/title>\n<meta name=\"description\" content=\"Eternidade Stealer, a Delphi-based banking trojan, spreads via WhatsApp hijacking and VBScript to steal contacts and financial credentials.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/cybersecuritynews.com\/new-malware-via-whatsapp-exfiltrate-contacts\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"New Malware Via WhatsApp Exfiltrate Contacts to Attack Server and Deploys Malware\" \/>\n<meta property=\"og:description\" content=\"Eternidade Stealer, a Delphi-based banking trojan, spreads via WhatsApp hijacking and VBScript to steal contacts and financial credentials.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/cybersecuritynews.com\/new-malware-via-whatsapp-exfiltrate-contacts\/\" \/>\n<meta property=\"og:site_name\" content=\"Cyber Security News\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hackingtutorialsandnews\" \/>\n<meta property=\"article:published_time\" content=\"2025-11-20T13:05:21+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjsRczYujxkV0dhyphenhyphentP3hITzlL90I8lTiPsubr3hcgAEMmXOyR3brX8RGlW6yxAXuVeoP4a6FlEmeKa0TpEkUOFRLJZPUuER4nmGs3BnrTykPUMy9TMnZQnofuBWhabnXt0XTusHv86ITvWrxRCDhzguO3zbtsjtVRYyPdq1JequbuJfgdItRLqlXL3Kbq4\/s16000\/New%20Malware%20Via%20WhatsApp%20Exfiltrate%20Contacts%20to%20Attack%20Server%20and%20Deploys%20Malware.webp\" \/><meta property=\"og:image\" content=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjsRczYujxkV0dhyphenhyphentP3hITzlL90I8lTiPsubr3hcgAEMmXOyR3brX8RGlW6yxAXuVeoP4a6FlEmeKa0TpEkUOFRLJZPUuER4nmGs3BnrTykPUMy9TMnZQnofuBWhabnXt0XTusHv86ITvWrxRCDhzguO3zbtsjtVRYyPdq1JequbuJfgdItRLqlXL3Kbq4\/s16000\/New%20Malware%20Via%20WhatsApp%20Exfiltrate%20Contacts%20to%20Attack%20Server%20and%20Deploys%20Malware.webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1600\" \/>\n\t<meta property=\"og:image:height\" content=\"900\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Tushar Subhra Dutta\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjsRczYujxkV0dhyphenhyphentP3hITzlL90I8lTiPsubr3hcgAEMmXOyR3brX8RGlW6yxAXuVeoP4a6FlEmeKa0TpEkUOFRLJZPUuER4nmGs3BnrTykPUMy9TMnZQnofuBWhabnXt0XTusHv86ITvWrxRCDhzguO3zbtsjtVRYyPdq1JequbuJfgdItRLqlXL3Kbq4\/s16000\/New%20Malware%20Via%20WhatsApp%20Exfiltrate%20Contacts%20to%20Attack%20Server%20and%20Deploys%20Malware.webp\" \/>\n<meta name=\"twitter:creator\" content=\"@The_Cyber_News\" \/>\n<meta name=\"twitter:site\" content=\"@The_Cyber_News\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Tushar Subhra Dutta\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"New Malware Via WhatsApp Exfiltrate Contacts to Attack Server and Deploys Malware","description":"Eternidade Stealer, a Delphi-based banking trojan, spreads via WhatsApp hijacking and VBScript to steal contacts and financial credentials.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/cybersecuritynews.com\/new-malware-via-whatsapp-exfiltrate-contacts\/","og_locale":"en_US","og_type":"article","og_title":"New Malware Via WhatsApp Exfiltrate Contacts to Attack Server and Deploys Malware","og_description":"Eternidade Stealer, a Delphi-based banking trojan, spreads via WhatsApp hijacking and VBScript to steal contacts and financial credentials.","og_url":"https:\/\/cybersecuritynews.com\/new-malware-via-whatsapp-exfiltrate-contacts\/","og_site_name":"Cyber Security News","article_publisher":"https:\/\/www.facebook.com\/Hackingtutorialsandnews","article_published_time":"2025-11-20T13:05:21+00:00","og_image":[{"url":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjsRczYujxkV0dhyphenhyphentP3hITzlL90I8lTiPsubr3hcgAEMmXOyR3brX8RGlW6yxAXuVeoP4a6FlEmeKa0TpEkUOFRLJZPUuER4nmGs3BnrTykPUMy9TMnZQnofuBWhabnXt0XTusHv86ITvWrxRCDhzguO3zbtsjtVRYyPdq1JequbuJfgdItRLqlXL3Kbq4\/s16000\/New%20Malware%20Via%20WhatsApp%20Exfiltrate%20Contacts%20to%20Attack%20Server%20and%20Deploys%20Malware.webp","type":"","width":"","height":""},{"width":1600,"height":900,"url":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjsRczYujxkV0dhyphenhyphentP3hITzlL90I8lTiPsubr3hcgAEMmXOyR3brX8RGlW6yxAXuVeoP4a6FlEmeKa0TpEkUOFRLJZPUuER4nmGs3BnrTykPUMy9TMnZQnofuBWhabnXt0XTusHv86ITvWrxRCDhzguO3zbtsjtVRYyPdq1JequbuJfgdItRLqlXL3Kbq4\/s16000\/New%20Malware%20Via%20WhatsApp%20Exfiltrate%20Contacts%20to%20Attack%20Server%20and%20Deploys%20Malware.webp","type":"image\/jpeg"}],"author":"Tushar Subhra Dutta","twitter_card":"summary_large_image","twitter_image":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjsRczYujxkV0dhyphenhyphentP3hITzlL90I8lTiPsubr3hcgAEMmXOyR3brX8RGlW6yxAXuVeoP4a6FlEmeKa0TpEkUOFRLJZPUuER4nmGs3BnrTykPUMy9TMnZQnofuBWhabnXt0XTusHv86ITvWrxRCDhzguO3zbtsjtVRYyPdq1JequbuJfgdItRLqlXL3Kbq4\/s16000\/New%20Malware%20Via%20WhatsApp%20Exfiltrate%20Contacts%20to%20Attack%20Server%20and%20Deploys%20Malware.webp","twitter_creator":"@The_Cyber_News","twitter_site":"@The_Cyber_News","twitter_misc":{"Written by":"Tushar Subhra Dutta","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"NewsArticle","@id":"https:\/\/cybersecuritynews.com\/new-malware-via-whatsapp-exfiltrate-contacts\/#article","isPartOf":{"@id":"https:\/\/cybersecuritynews.com\/new-malware-via-whatsapp-exfiltrate-contacts\/"},"author":{"name":"Tushar Subhra Dutta","@id":"https:\/\/cybersecuritynews.com\/#\/schema\/person\/7eb7d8d026aa5dd566f134d4def5c05c"},"headline":"New Malware Via WhatsApp Exfiltrate Contacts to Attack Server and Deploys Malware","datePublished":"2025-11-20T13:05:21+00:00","mainEntityOfPage":{"@id":"https:\/\/cybersecuritynews.com\/new-malware-via-whatsapp-exfiltrate-contacts\/"},"wordCount":485,"publisher":{"@id":"https:\/\/cybersecuritynews.com\/#organization"},"image":{"@id":"https:\/\/cybersecuritynews.com\/new-malware-via-whatsapp-exfiltrate-contacts\/#primaryimage"},"thumbnailUrl":"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjsRczYujxkV0dhyphenhyphentP3hITzlL90I8lTiPsubr3hcgAEMmXOyR3brX8RGlW6yxAXuVeoP4a6FlEmeKa0TpEkUOFRLJZPUuER4nmGs3BnrTykPUMy9TMnZQnofuBWhabnXt0XTusHv86ITvWrxRCDhzguO3zbtsjtVRYyPdq1JequbuJfgdItRLqlXL3Kbq4\/s16000\/New%20Malware%20Via%20WhatsApp%20Exfiltrate%20Contacts%20to%20Attack%20Server%20and%20Deploys%20Malware.webp?w=1600&resize=1600,900&ssl=1","keywords":["cyber security","cyber security news"],"articleSection":["Cyber Security News","Threats"],"inLanguage":"en-US","copyrightYear":"2025","copyrightHolder":{"@id":"https:\/\/cybersecuritynews.com\/#organization"}},{"@type":"WebPage","@id":"https:\/\/cybersecuritynews.com\/new-malware-via-whatsapp-exfiltrate-contacts\/","url":"https:\/\/cybersecuritynews.com\/new-malware-via-whatsapp-exfiltrate-contacts\/","name":"New Malware Via WhatsApp Exfiltrate Contacts to Attack Server and Deploys Malware","isPartOf":{"@id":"https:\/\/cybersecuritynews.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/cybersecuritynews.com\/new-malware-via-whatsapp-exfiltrate-contacts\/#primaryimage"},"image":{"@id":"https:\/\/cybersecuritynews.com\/new-malware-via-whatsapp-exfiltrate-contacts\/#primaryimage"},"thumbnailUrl":"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjsRczYujxkV0dhyphenhyphentP3hITzlL90I8lTiPsubr3hcgAEMmXOyR3brX8RGlW6yxAXuVeoP4a6FlEmeKa0TpEkUOFRLJZPUuER4nmGs3BnrTykPUMy9TMnZQnofuBWhabnXt0XTusHv86ITvWrxRCDhzguO3zbtsjtVRYyPdq1JequbuJfgdItRLqlXL3Kbq4\/s16000\/New%20Malware%20Via%20WhatsApp%20Exfiltrate%20Contacts%20to%20Attack%20Server%20and%20Deploys%20Malware.webp?w=1600&resize=1600,900&ssl=1","datePublished":"2025-11-20T13:05:21+00:00","description":"Eternidade Stealer, a Delphi-based banking trojan, spreads via WhatsApp hijacking and VBScript to steal contacts and financial credentials.","breadcrumb":{"@id":"https:\/\/cybersecuritynews.com\/new-malware-via-whatsapp-exfiltrate-contacts\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/cybersecuritynews.com\/new-malware-via-whatsapp-exfiltrate-contacts\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/cybersecuritynews.com\/new-malware-via-whatsapp-exfiltrate-contacts\/#primaryimage","url":"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjsRczYujxkV0dhyphenhyphentP3hITzlL90I8lTiPsubr3hcgAEMmXOyR3brX8RGlW6yxAXuVeoP4a6FlEmeKa0TpEkUOFRLJZPUuER4nmGs3BnrTykPUMy9TMnZQnofuBWhabnXt0XTusHv86ITvWrxRCDhzguO3zbtsjtVRYyPdq1JequbuJfgdItRLqlXL3Kbq4\/s16000\/New%20Malware%20Via%20WhatsApp%20Exfiltrate%20Contacts%20to%20Attack%20Server%20and%20Deploys%20Malware.webp?w=1600&resize=1600,900&ssl=1","contentUrl":"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjsRczYujxkV0dhyphenhyphentP3hITzlL90I8lTiPsubr3hcgAEMmXOyR3brX8RGlW6yxAXuVeoP4a6FlEmeKa0TpEkUOFRLJZPUuER4nmGs3BnrTykPUMy9TMnZQnofuBWhabnXt0XTusHv86ITvWrxRCDhzguO3zbtsjtVRYyPdq1JequbuJfgdItRLqlXL3Kbq4\/s16000\/New%20Malware%20Via%20WhatsApp%20Exfiltrate%20Contacts%20to%20Attack%20Server%20and%20Deploys%20Malware.webp?w=1600&resize=1600,900&ssl=1","width":"1600","height":"900"},{"@type":"BreadcrumbList","@id":"https:\/\/cybersecuritynews.com\/new-malware-via-whatsapp-exfiltrate-contacts\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/cybersecuritynews.com\/"},{"@type":"ListItem","position":2,"name":"New Malware Via WhatsApp Exfiltrate Contacts to Attack Server and Deploys Malware"}]},{"@type":"WebSite","@id":"https:\/\/cybersecuritynews.com\/#website","url":"https:\/\/cybersecuritynews.com\/","name":"Cyber Security News","description":"World&#039;s #1 Premier Cybersecurity and Hacking News Portal","publisher":{"@id":"https:\/\/cybersecuritynews.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/cybersecuritynews.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/cybersecuritynews.com\/#organization","name":"Cyber Security News","url":"https:\/\/cybersecuritynews.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/cybersecuritynews.com\/#\/schema\/logo\/image\/","url":"https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2021\/06\/Cyber-security.jpg","contentUrl":"https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2021\/06\/Cyber-security.jpg","width":200,"height":200,"caption":"Cyber Security News"},"image":{"@id":"https:\/\/cybersecuritynews.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hackingtutorialsandnews","https:\/\/x.com\/The_Cyber_News","https:\/\/www.linkedin.com\/company\/cybersecurity-news\/"]},{"@type":"Person","@id":"https:\/\/cybersecuritynews.com\/#\/schema\/person\/7eb7d8d026aa5dd566f134d4def5c05c","name":"Tushar Subhra Dutta","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/cybersecuritynews.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/f8bc0247220c7d4dea6c8b5a77d910613305ead17b13c2a7920b400435a848dd?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f8bc0247220c7d4dea6c8b5a77d910613305ead17b13c2a7920b400435a848dd?s=96&d=mm&r=g","caption":"Tushar Subhra Dutta"},"description":"Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.","url":"https:\/\/cybersecuritynews.com\/author\/tushar\/"}]}},"jetpack_featured_media_url":"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjsRczYujxkV0dhyphenhyphentP3hITzlL90I8lTiPsubr3hcgAEMmXOyR3brX8RGlW6yxAXuVeoP4a6FlEmeKa0TpEkUOFRLJZPUuER4nmGs3BnrTykPUMy9TMnZQnofuBWhabnXt0XTusHv86ITvWrxRCDhzguO3zbtsjtVRYyPdq1JequbuJfgdItRLqlXL3Kbq4\/s16000\/New%20Malware%20Via%20WhatsApp%20Exfiltrate%20Contacts%20to%20Attack%20Server%20and%20Deploys%20Malware.webp?w=1600&resize=1600,900&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/posts\/133859","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/comments?post=133859"}],"version-history":[{"count":1,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/posts\/133859\/revisions"}],"predecessor-version":[{"id":133885,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/posts\/133859\/revisions\/133885"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/media\/133886"}],"wp:attachment":[{"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/media?parent=133859"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/categories?post=133859"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/tags?post=133859"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}