logo

Astaroth, Mekotio & Ousaban abusing Google Cloud Run in LATAM-focused malware campaigns

ID: 4f71543e-b5a2-57e5-be05-2fe3a4727222

STIX ID: report--4f71543e-b5a2-57e5-be05-2fe3a4727222

Feed Name: Cisco Talos

Threat Score
75/100

Date Published: 2024-02-20

Date Updated: 2026-04-27

Author: Edmund Brumaghin

...
...

Cisco Talos describes a sustained, high-volume malspam campaign abusing Google Cloud Run and Google Cloud Storage to distribute banking trojans (Astaroth/Guildma, Mekotio, Ousaban) primarily targeting Latin America. The report details MSI-based droppers, AutoIt-based loaders, DLL injection and living-off-the-land techniques, provides hashes, URLs, domains and an IP, and offers detection and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.