Skip to main content

Threats Tagged 'astaroth'

View all threats tagged with 'astaroth'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: astaroth

Threats Tagged 'astaroth'

Click on any threat for detailed analysis and mitigation recommendations

The Boto Cor-de-Rosa campaign reveals Astaroth's new strategy of exploiting WhatsApp Web for propagation. This Brazilian banking malware now uses a Python-based worm module to retrieve victims' WhatsApp contact lists and automatically send malicious messages, expanding its infection reach. The attack begins with a malicious ZIP file sent via WhatsApp, containing a Visual Basic script that downloads additional components. The malware then operates two parallel modules: a propagation module for spreading through WhatsApp contacts, and a banking module for credential stealing. This campaign demonstrates Astaroth's evolution, combining traditional malware techniques with sophisticated social engineering and multi-platform propagation, primarily targeting Brazilian users.

Join the discussion

A malware campaign targeting WhatsApp users primarily in Brazil uses WhatsApp's 'View Once' message feature to deliver malicious ZIP archives containing VBS or HTA files. These files execute PowerShell scripts to download additional payloads, including scripts that steal WhatsApp user data and an MSI installer deploying the Astaroth banking trojan. The campaign evolved from IMAP-based to HTTP-based command and control communication and leverages Selenium Chrome WebDriver and the WPPConnect JavaScript library to hijack WhatsApp Web sessions, steal session tokens and contacts, and distribute spam. Over 250 victims have been identified, with 95% located in Brazil and some impact noted in Austria. The attack enables credential theft, session hijacking, persistence, and financial fraud through banking trojan deployment. No CVE or known exploits in the wild are reported, and the campaign is rated medium severity. Defenders should focus on user awareness, endpoint detection of PowerShell and script execution, and monitoring for suspicious WhatsApp Web activity.

Join the discussion

A new Astaroth banking trojan campaign has been discovered abusing GitHub to host malware configurations. The infection begins with a phishing email containing a link to download a zipped Windows shortcut file, which installs the Astaroth malware. The trojan detects when users access banking or cryptocurrency websites and steals credentials through keylogging. It sends stolen information to attackers using Ngrok reverse proxy and uses GitHub to update its configuration when command and control servers become inaccessible. The malware primarily targets South American countries, with a focus on Brazil. Astaroth employs various anti-analysis techniques and targets specific banking and cryptocurrency-related sites. The GitHub repositories hosting the malicious configurations have been reported and taken down.

Join the discussion

Showing 1 to 3 of 3 results

Filters:Tag: astaroth
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses