logo

Astaroth: Banking Trojan Abusing GitHub for Resilience

ID: 2f20ac80-eb6b-58df-983e-7415b9470639

STIX ID: report--2f20ac80-eb6b-58df-983e-7415b9470639

Feed Name: McAfee Labs Blog

Threat Score
75/100

Date Published: 2025-10-11

Date Updated: 2026-04-28

Author: McAfee Labs

...
...

McAfee researchers uncovered an active Astaroth campaign that infects victims via phishing ZIPs containing LNK files which launch obfuscated JavaScript and AutoIT components; the Delphi-based payload performs keylogging and credential theft against banking and cryptocurrency sites, exfiltrating data via ngrok-based C2s. The actors use GitHub-hosted images with steganographically embedded configuration as resilient backup infrastructure for updates when primary C2s are disrupted; the report includes technical analysis, targeted site lists, persistence details, and numerous IOCs (hashes, URLs, GitHub repos).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.