logo

Astaroth banking Trojan spreads in Brazil via WhatsApp worm

ID: 37ac16d3-736e-5a59-954b-99c21b17219a

STIX ID: report--37ac16d3-736e-5a59-954b-99c21b17219a

Feed Name: Security Affairs

Threat Score
72/100

Date Published: 2026-01-08

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Astaroth's recent 'Boto Cor‑de‑Rosa' campaign in Brazil uses malicious ZIPs sent via WhatsApp to deploy an obfuscated VBScript downloader that installs both a Delphi-based banking trojan and a Python-based WhatsApp worm. The worm harvests contacts and auto-sends infected ZIPs with localized Portuguese lures while a background banking module monitors browsing and steals credentials; the report includes IoCs and highlights the campaign's social-engineering propagation and multi-language, modular toolset.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.