As far as I'm concerned, these seems to come in ZIP archives with the LNK calling the BAT and at the very least, get distributed through #WhatsApp.
And potentially through cliente[.]rte[.]com[.]br a few days ago.
Don't have access to the WhatsApp Web on the compromised systems.
'HealthApp-a00697.bat' is a FUD from Brazil @abuse_ch
bazaar.abuse.ch/sample/cfe65…
expansiveuser(.)com
Same domain as below 👇
Oct 2, 2025 · 2:18 AM UTC

