logo

Astaroth (Guildma) Uses Steganography and Ngrok for C2 Resilience

ID: 9169937d-02b0-52c1-9bc3-45a25c821463

STIX ID: report--9169937d-02b0-52c1-9bc3-45a25c821463

Feed Name: Picus Security Articles

Threat Score
75/100

Date Published: 2026-07-28

Date Updated: 2026-07-28

Author: [email protected] (Umut Bayram)

...
...

**Executive summary:** Astaroth (Guildma) is a Delphi-based Windows banking trojan active since 2018 and heavily focused on Brazil; it is delivered via phishing (email spoofing DocuSign/government) and WhatsApp lures, uses multi-stage AutoIt/MSI loaders with in-memory injection and process hollowing, employs extensive sandbox/analysis checks (locale, volume serial, tool blocklists) and forced shutdown on detection, installs system-wide keylogging when targeted banking/crypto browser windows are active, exfiltrates data over TCP through Ngrok tunnels, and refreshes encrypted configuration from steganographic images to increase resilience — Picus provides simulation modules to validate defenses against these behaviors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.