As far as I'm concerned, these seems to come in ZIP archives with the LNK calling the BAT and at the very least, get distributed through #WhatsApp. And potentially through cliente[.]rte[.]com[.]br a few days ago. Don't have access to the WhatsApp Web on the compromised systems.
'HealthApp-a00697.bat' is a FUD from Brazil @abuse_ch bazaar.abuse.ch/sample/cfe65… expansiveuser(.)com Same domain as below 👇

Oct 2, 2025 · 2:18 AM UTC