“Boto Cor-de-Rosa”: Banking Malware Astaroth Pivots to WhatsApp in New Campaign
ID: 12c81c92-aa17-5ed0-8c24-3562523834bf
STIX ID: report--12c81c92-aa17-5ed0-8c24-3562523834bf
Feed Name: securityonline.info
Threat Score
Acronis Threat Research Unit discovered a campaign named “Boto Cor-de-Rosa” in which the Astaroth banking malware has been extended with a Python-based worm that hijacks WhatsApp Web sessions to send malicious ZIP archives to a victim's contacts, exfiltrate contact lists, and report propagation statistics to operators; the campaign combines credential theft with messaging-based propagation to increase infection success.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
