Astaroth Banking Trojan Targets Brazilians via WhatsApp Messages
ID: f5862021-20f8-5820-84b5-a175f4c756e7
STIX ID: report--f5862021-20f8-5820-84b5-a175f4c756e7
Feed Name: HackRead
Threat Score
Acronis Threat Research Unit details the Boto Cor-de-Rosa campaign: a variant of the Astaroth banking trojan that propagates via WhatsApp by sending ZIP attachments which drop a Delphi banking module and a Python-based spreader (zapbiu.py). The malware steals contact lists to self-propagate, monitors for banking logins, hides its files under C:\Public\MicrosoftEdgeCache_6.60.2.9313, uses Portuguese greetings to social-engineer Brazilian victims, and tracks propagation progress.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
