Quick Summary
The Securityish Brief
Cybersecurity researchers have identified a campaign that leverages WhatsApp to distribute the Astaroth banking trojan, specifically targeting users in Brazil. This campaign, referred to as Boto Cor-de-Rosa by Acronis Threat Research Unit, retrieves victims’ WhatsApp contact lists and sends malicious messages to propagate the malware. The Astaroth trojan, also known as Guildma, has been active since 2015 and is known for data theft, particularly in Latin America.
The campaign began around September 24, 2025, and has impacted over 95% of devices in Brazil, with some instances reported in the U.S. and Austria. The malware distribution involves ZIP archives that contain a downloader script, which retrieves a PowerShell or Python script for further data collection and malware installation. The use of WhatsApp for such attacks is a new tactic, reflecting the platform’s popularity in Brazil.
Astaroth’s architecture includes a Python-based propagation module that automatically forwards malicious ZIP files to contacts, enhancing its worm-like spread. Additionally, a banking module monitors victims’ web activity to harvest credentials when they visit banking sites. The malware also tracks its propagation metrics, logging successful and failed message deliveries.
Understanding the Threat Landscape
This incident highlights the evolving tactics of cybercriminals, particularly their adaptation to popular communication platforms like WhatsApp. The integration of multi-language components in malware signifies a growing sophistication in attack methods. The campaign’s reliance on social engineering through trusted contacts makes it particularly dangerous for users.
Organizations and individuals must remain vigilant against such threats, as the use of familiar platforms for malicious purposes can easily deceive users. Regular monitoring of communications and being cautious with unexpected messages can help mitigate risks associated with such malware.
Key Takeaways
- Be cautious of unexpected messages from contacts on WhatsApp, especially those containing links or attachments.
- Regularly update your device and applications to protect against known vulnerabilities.
- Monitor your online banking activity for any unauthorized transactions or unusual behavior.
- Educate yourself and others about the signs of phishing and malware distribution tactics.
- Consider using security software that can detect and block malware threats.
Key Terms & Concepts
- Astaroth: In this article, Astaroth refers to a banking trojan that targets users primarily in Latin America for data theft.
- Boto Cor-de-Rosa: Boto Cor-de-Rosa is the codename for a malware campaign that spreads the Astaroth trojan via WhatsApp.
- Propagation module: A propagation module is a component of malware designed to spread itself to other devices or users.
- Visual Basic Script: Visual Basic Script is a scripting language used for automating tasks in Windows, which can be exploited by malware.
- Python: Python is a programming language that has been used to develop a module in the Astaroth trojan for spreading malware.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.