Skip to content

Astaroth

Guildma, also known as Astaroth, is a modular Brazilian banking trojan active since at least 2015.

Profile source: Mallory opens in a new tab

Astaroth

Family profile

Guildma, also known as Astaroth, is a modular Brazilian banking trojan active since at least 2015. It combines remote-access, spyware, credential-theft, banking-fraud, and spam-distribution functions, primarily targeting Windows users. Initially concentrated on Brazilian financial institutions and users, Guildma later expanded its targeting to banks and online services across Latin America, Europe, and China. It has been distributed chiefly through Portuguese-language phishing lures impersonating invoices, tax documents, contracts, and similar business communications. Delivery chains commonly use archive attachments containing malicious shortcuts, VBScript, HTML, or JavaScript components to retrieve staged payloads; campaigns have also applied Brazilian geofencing and locale checks. Guildma uses a multi-stage architecture with Delphi-based loaders, injectors, RAT components, a banking core, credential-stealing modules, and a mailer component. Its capabilities include monitoring browsers and banking applications, capturing screenshots and keystrokes, stealing passwords, credentials, payment-card data, contacts, and email-client metadata, and sending collected data to command-and-control infrastructure. It can establish persistence through Windows startup mechanisms, hide execution windows, store payload content in NTFS alternate data streams, enumerate processes, collect host time and external network-address information, encode C2 data with Base64, and use process hollowing to execute within legitimate processes. Guildma also incorporates anti-emulation and localization checks and has used legitimate password-recovery utilities as supplementary credential-theft components.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Keylogging
  • Persistence
  • Process Injection
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 23, 2026
Last activity
Sep 23, 2026
Feed role
C2 / Distribution
Host form
0 IP / 2 hostnames

Leading locations

  • FR1

Leading providers

  • Contabo GmbH1

Infrastructure traits

  • Hosting 1

Reported operators

Threat actors

2 named in public reporting
TA2725

TA2725 is a threat actor Proofpoint tracked since March 2022 that is known for using Brazilian banking malware (including Mispadu, Astaroth, and historically Grandoreiro) and credential phishing to target organizations mainly in Brazil, Mexico, and Spain.

stac3150

...another set of attacks has led to the deployment of the Astaroth banking trojan. Sophos is tracking the second cluster under the moniker STAC3150 since September 24, 2025.

MITRE ATT&CK

Astaroth in ATT&CK

99 distinct techniques

Techniques

99 techniques
T1566.002 Spearphishing Link T1204.002 Malicious File T1614 System Location Discovery T1071.001 Web Protocols T1614.001 System Language Discovery T1564.004 NTFS File Attributes T1105 Ingress Tool Transfer T1218 System Binary Proxy Execution T1555 Credentials from Password Stores T1132 Data Encoding T1057 Process Discovery T1082 System Information Discovery T1566.001 Spearphishing Attachment T1547.001 Registry Run Keys / Startup Folder T1555.003 Credentials from Web Browsers T1518.001 Security Software Discovery T1566 Phishing T1547.009 Shortcut Modification T1056.003 Web Portal Capture T1218.010 Regsvr32 T1059.003 Windows Command Shell T1016 System Network Configuration Discovery T1041 Exfiltration Over C2 Channel T1055 Process Injection T1560 Archive Collected Data T1204 User Execution T1059 Command and Scripting Interpreter T1083 File and Directory Discovery T1059.005 Visual Basic T1574.001 DLL T1555.001 Keychain T1027 Obfuscated Files or Information T1518 Software Discovery T1012 Query Registry T1056.001 Keylogging T1220 XSL Script Processing T1124 System Time Discovery T1529 System Shutdown/Reboot T1059.007 JavaScript T1497.001 System Checks T1055.012 Process Hollowing T1140 Deobfuscate/Decode Files or Information T1598 Phishing for Information T1564.003 Hidden Window T1070.004 File Deletion T1219 Remote Access Tools T1113 Screen Capture T1070.009 Clear Persistence T1197 BITS Jobs T1059.001 PowerShell T1218.003 CMSTP T1218.001 Compiled HTML File T1218.005 Mshta T1620 Reflective Code Loading T1071 Application Layer Protocol T1562 Impair Defenses T1047 Windows Management Instrumentation T1056 Input Capture T1497 Virtualization/Sandbox Evasion T1036 Masquerading T1010 Application Window Discovery T1622 Debugger Evasion T1036.005 Match Legitimate Resource Name or Location T1552.001 Credentials In Files T1568 Dynamic Resolution T1132.001 Standard Encoding T1048 Exfiltration Over Alternative Protocol T1132.002 Non-Standard Encoding T1218.011 Rundll32 T1102 Web Service T1112 Modify Registry T1056.002 GUI Input Capture T1185 Browser Session Hijacking T1119 Automated Collection T1539 Steal Web Session Cookie T1589 Gather Victim Identity Information T1566.003 Spearphishing via Service T1115 Clipboard Data T1528 Steal Application Access Token T1059.006 Python T1027.003 Steganography T1564.001 Hidden Files and Directories T1649 Steal or Forge Authentication Certificates T1074 Data Staged T1027.013 Encrypted/Encoded File T1218.004 InstallUtil T1027.010 Command Obfuscation T1553 Subvert Trust Controls T1552 Unsecured Credentials T1497.003 Time Based Checks T1036.008 Masquerade File Type T1129 Shared Modules T1027.002 Software Packing T1568.002 Domain Generation Algorithms T1574 Hijack Execution Flow T1543 Create or Modify System Process T1005 Data from Local System T1074.001 Local Data Staging T1102.001 Dead Drop Resolver

Reporting

Research mentioning Astaroth

Aug 13
Malware News

Armored Likho expands its cyber-espionage toolkit - Malware News - Malware Analysis, News and Indicators

Armored Likho, also tracked as Eagle Werewolf, launched a cyber-espionage campaign against private users and organizations in Russia, including targets in government, corporate, IT, and education sectors. The operation used fake charity-assistance applications built as Rust/Tauri droppers to install a new modular espionage framework called Still Toolkit. Its Still Sync component steals Telegram Desktop session data, authenticates to victims’ Telegram accounts, and exfiltrates chats, media, and account details through the Telegram API, while Still Audio covertly activates microphone surveillance by detecting speech and uploading recordings to command-and-control servers.

Aug 13
Securelist Ru

Новые инструменты Armored Likho нацелены на Telegram и прослушку | Securelist

Aug 13
Securelist

New Armored Likho tools target Telegram and eavesdropping | Securelist

Aug 11
Lazarusholic Bluesky

Post by @lazarusholic.bsky.social - Bluesky

A Sonatype report identified six malicious npm packages that used Ethereum transactions to retrieve and stage malicious payloads, an unusual delivery method that obscures second-stage infrastructure behind blockchain activity. The campaign was linked in public reporting to ContagiousInterview and NullReceiver, indicating continued abuse of the JavaScript and Node.js ecosystem for software supply-chain compromise. The activity aligns with broader attacker tradecraft documented for MITRE ATT&CK T1059.007 (Command and Scripting Interpreter: JavaScript), which covers JavaScript and Node.js use for payload delivery, execution, reconnaissance, and command-and-control. Defenders monitoring follow-on behavior should watch for suspicious child-process activity and discovery commands launched from non-shell parent processes, a pattern reflected in Splunk detection guidance for tools such as ipconfig.exe, systeminfo.exe, net.exe, and whoami.exe executed outside normal cmd.exe or PowerShell chains.

May 13
Splunk Research

Detection: Cmdline Tool Not Executed In CMD Shell | Splunk Security Content

Apr 16
Bi Zone

Unholy trinity: werewolves target law enforces | Learn more

Feb 16
Bi Zone

Триединое зло: "оборотни" атакуют сотрудников силовых структур - читайте на BI.ZONE

Nov 2
Cyble Blog Historic

Cyble - New Laplas Clipper Distributed Via SmokeLoader

Researchers reported multiple financially motivated malware campaigns using SmokeLoader as a delivery mechanism for follow-on payloads including Gozi ISFB, ZLoader, Oski, AveMaria, Cobalt Strike, SystemBC, RecordBreaker, and the Laplas Clipper cryptocurrency hijacker. In one campaign set, attackers abused website contact forms and sent phishing lures posing as copyright complaints, directing victims to malicious documents hosted on legitimate services such as Google Drive. Talos found the initial payloads were wrapped in a shared crypter identified by the DOS-stub string "Salfram," indicating a common tooling layer across otherwise varied malware deliveries. The activity relied on evasive and modular infection chains designed to complicate detection and maximize monetization. The Salfram crypter used obfuscation methods including fake API calls, fragmented control flow, self-modifying code, and memory allocation through ZwAllocateVirtualMemory, while later-stage malware added persistence and theft capabilities. Cyble said Laplas Clipper monitored the clipboard for cryptocurrency wallet addresses, pulled regex patterns and replacement addresses from clipper[.]guru, and persisted by copying itself into %appdata% and creating a scheduled task that ran every minute. The combined use of phishing, legitimate hosting platforms, crypter-based obfuscation, and multi-payload delivery shows an adaptable criminal ecosystem built to steal credentials, proxy access, banking data, and cryptocurrency funds.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.