Astaroth unleashed
ID: 8e4d8ede-92b8-5313-8f45-4df5b33fad5a
STIX ID: report--8e4d8ede-92b8-5313-8f45-4df5b33fad5a
Feed Name: TRU Security by Acronis
Acronis Threat Research Unit (TRU) analyzed an active Astaroth (Guildma) malware campaign primarily targeting Latin America—notably Brazil—affecting manufacturing, IT, financial services and healthcare; the report details a multi-stage infection chain (malicious LNK → JavaScript downloader → PowerShell → AutoIt loader → in-memory DLL/Astaroth binary), advanced evasion (steganography, geofencing, sandbox/hard-drive checks), persistence mechanisms, encrypted configuration files, and provides IOCs (sample hashes and C2 URLs) along with detection notes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
