Threats Tagged 'astaroth'
View all threats tagged with 'astaroth'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'astaroth'
Click on any threat for detailed analysis and mitigation recommendations
The Boto Cor-de-Rosa campaign reveals Astaroth's new strategy of exploiting WhatsApp Web for propagation. This Brazilian banking malware now uses a Python-based worm module to retrieve victims' WhatsApp contact lists and automatically send malicious messages, expanding its infection reach. The attack begins with a malicious ZIP file sent via WhatsApp, containing a Visual Basic script that downloads additional components. The malware then operates two parallel modules: a propagation module for spreading through WhatsApp contacts, and a banking module for credential stealing. This campaign demonstrates Astaroth's evolution, combining traditional malware techniques with sophisticated social engineering and multi-platform propagation, primarily targeting Brazilian users. Join the discussion | AlienVault OTX General | 01/08/2026, 18:12:03 UTC Added: 01/09/2026, 09:26:35 UTC |
A malware campaign targeting WhatsApp users primarily in Brazil uses WhatsApp's 'View Once' message feature to deliver malicious ZIP archives containing VBS or HTA files. These files execute PowerShell scripts to download additional payloads, including scripts that steal WhatsApp user data and an MSI installer deploying the Astaroth banking trojan. The campaign evolved from IMAP-based to HTTP-based command and control communication and leverages Selenium Chrome WebDriver and the WPPConnect JavaScript library to hijack WhatsApp Web sessions, steal session tokens and contacts, and distribute spam. Over 250 victims have been identified, with 95% located in Brazil and some impact noted in Austria. The attack enables credential theft, session hijacking, persistence, and financial fraud through banking trojan deployment. No CVE or known exploits in the wild are reported, and the campaign is rated medium severity. Defenders should focus on user awareness, endpoint detection of PowerShell and script execution, and monitoring for suspicious WhatsApp Web activity. Join the discussion | AlienVault OTX General | 11/20/2025, 19:42:41 UTC Added: 11/20/2025, 22:13:41 UTC |
A new Astaroth banking trojan campaign has been discovered abusing GitHub to host malware configurations. The infection begins with a phishing email containing a link to download a zipped Windows shortcut file, which installs the Astaroth malware. The trojan detects when users access banking or cryptocurrency websites and steals credentials through keylogging. It sends stolen information to attackers using Ngrok reverse proxy and uses GitHub to update its configuration when command and control servers become inaccessible. The malware primarily targets South American countries, with a focus on Brazil. Astaroth employs various anti-analysis techniques and targets specific banking and cryptocurrency-related sites. The GitHub repositories hosting the malicious configurations have been reported and taken down. Join the discussion | AlienVault OTX General | 10/14/2025, 09:10:41 UTC Added: 10/14/2025, 09:21:37 UTC |
Showing 1 to 3 of 3 results