Last seven days
- First activity
- Sep 23, 2026
- Last activity
- Sep 23, 2026
- Feed role
- C2 / Distribution
- Host form
- 0 IP / 2 hostnames
Guildma, also known as Astaroth, is a modular Brazilian banking trojan active since at least 2015.
Profile source: Mallory opens in a new tabAstaroth
Guildma, also known as Astaroth, is a modular Brazilian banking trojan active since at least 2015. It combines remote-access, spyware, credential-theft, banking-fraud, and spam-distribution functions, primarily targeting Windows users. Initially concentrated on Brazilian financial institutions and users, Guildma later expanded its targeting to banks and online services across Latin America, Europe, and China. It has been distributed chiefly through Portuguese-language phishing lures impersonating invoices, tax documents, contracts, and similar business communications. Delivery chains commonly use archive attachments containing malicious shortcuts, VBScript, HTML, or JavaScript components to retrieve staged payloads; campaigns have also applied Brazilian geofencing and locale checks. Guildma uses a multi-stage architecture with Delphi-based loaders, injectors, RAT components, a banking core, credential-stealing modules, and a mailer component. Its capabilities include monitoring browsers and banking applications, capturing screenshots and keystrokes, stealing passwords, credentials, payment-card data, contacts, and email-client metadata, and sending collected data to command-and-control infrastructure. It can establish persistence through Windows startup mechanisms, hide execution windows, store payload content in NTFS alternate data streams, enumerate processes, collect host time and external network-address information, encode C2 data with Base64, and use process hollowing to execute within legitimate processes. Guildma also incorporates anti-emulation and localization checks and has used legitimate password-recovery utilities as supplementary credential-theft components.
C2 tracking
Derp observations, rolling seven-day window
Reported operators
TA2725 is a threat actor Proofpoint tracked since March 2022 that is known for using Brazilian banking malware (including Mispadu, Astaroth, and historically Grandoreiro) and credential phishing to target organizations mainly in Brazil, Mexico, and Spain.
...another set of attacks has led to the deployment of the Astaroth banking trojan. Sophos is tracking the second cluster under the moniker STAC3150 since September 24, 2025.
MITRE ATT&CK
Reporting
Armored Likho, also tracked as Eagle Werewolf, launched a cyber-espionage campaign against private users and organizations in Russia, including targets in government, corporate, IT, and education sectors. The operation used fake charity-assistance applications built as Rust/Tauri droppers to install a new modular espionage framework called Still Toolkit. Its Still Sync component steals Telegram Desktop session data, authenticates to victims’ Telegram accounts, and exfiltrates chats, media, and account details through the Telegram API, while Still Audio covertly activates microphone surveillance by detecting speech and uploading recordings to command-and-control servers.
A Sonatype report identified six malicious npm packages that used Ethereum transactions to retrieve and stage malicious payloads, an unusual delivery method that obscures second-stage infrastructure behind blockchain activity. The campaign was linked in public reporting to ContagiousInterview and NullReceiver, indicating continued abuse of the JavaScript and Node.js ecosystem for software supply-chain compromise. The activity aligns with broader attacker tradecraft documented for MITRE ATT&CK T1059.007 (Command and Scripting Interpreter: JavaScript), which covers JavaScript and Node.js use for payload delivery, execution, reconnaissance, and command-and-control. Defenders monitoring follow-on behavior should watch for suspicious child-process activity and discovery commands launched from non-shell parent processes, a pattern reflected in Splunk detection guidance for tools such as ipconfig.exe, systeminfo.exe, net.exe, and whoami.exe executed outside normal cmd.exe or PowerShell chains.
Researchers reported multiple financially motivated malware campaigns using SmokeLoader as a delivery mechanism for follow-on payloads including Gozi ISFB, ZLoader, Oski, AveMaria, Cobalt Strike, SystemBC, RecordBreaker, and the Laplas Clipper cryptocurrency hijacker. In one campaign set, attackers abused website contact forms and sent phishing lures posing as copyright complaints, directing victims to malicious documents hosted on legitimate services such as Google Drive. Talos found the initial payloads were wrapped in a shared crypter identified by the DOS-stub string "Salfram," indicating a common tooling layer across otherwise varied malware deliveries. The activity relied on evasive and modular infection chains designed to complicate detection and maximize monetization. The Salfram crypter used obfuscation methods including fake API calls, fragmented control flow, self-modifying code, and memory allocation through ZwAllocateVirtualMemory, while later-stage malware added persistence and theft capabilities. Cyble said Laplas Clipper monitored the clipboard for cryptocurrency wallet addresses, pulled regex patterns and replacement addresses from clipper[.]guru, and persisted by copying itself into %appdata% and creating a scheduled task that ran every minute. The combined use of phishing, legitimate hosting platforms, crypter-based obfuscation, and multi-payload delivery shows an adaptable criminal ecosystem built to steal credentials, proxy access, banking data, and cryptocurrency funds.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.