logo

“Boto Cor-de-Rosa”: Banking Malware Astaroth Pivots to WhatsApp in New Campaign

ID: 12c81c92-aa17-5ed0-8c24-3562523834bf

STIX ID: report--12c81c92-aa17-5ed0-8c24-3562523834bf

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-01-12

Date Updated: 2026-04-23

Author: Ddos

...
...

Acronis Threat Research Unit discovered a campaign named “Boto Cor-de-Rosa” in which the Astaroth banking malware has been extended with a Python-based worm that hijacks WhatsApp Web sessions to send malicious ZIP archives to a victim's contacts, exfiltrate contact lists, and report propagation statistics to operators; the campaign combines credential theft with messaging-based propagation to increase infection success.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.