logo

Boto-Cor-de-Rosa campaign reveals Astaroth WhatsApp-based worm activity in Brazil

ID: 87a70918-463e-51b0-bf3b-5dec8dba586c

STIX ID: report--87a70918-463e-51b0-bf3b-5dec8dba586c

Feed Name: TRU Security by Acronis

Threat Score
75/100

Date Published: 2026-01-08

Date Updated: 2026-07-24

...
...

Astaroth's latest Brazilian-focused campaign (Boto Cor-de-Rosa) combines a Delphi/AutoIt-based banking infostealer with a new Python WhatsApp spreader (zapbiu.py) that harvests contacts, sends malicious ZIPs with an obfuscated VBS downloader, installs an MSI dropper, and exfiltrates contact lists; the report includes technical analysis, propagation and banking module descriptions, numerous file hashes, and at least one contacted domain, with detection noted by Acronis.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.