Astaroth, also known as Guildma, is a Windows banking trojan combining credential theft, spyware, and remote-access capabilities. It targets financial-account credentials and other sensitive information, including passwords, one-time passwords, browser cookies, and keystrokes. It can use the external NetPass password-recovery utility to obtain passwords and exfiltrates collected information to command-and-control servers, with observed use of Base64 encoding for transmitted data. Campaigns have targeted Brazilian users through Brazilian Portuguese phishing messages.
Distribution mechanisms include malicious email attachments, VBScript attachments, and links delivering ZIP archives containing Windows shortcuts. Observed infection chains retrieve a DLL into an NTFS alternate data stream and subsequently install a compiled AutoIt payload. Some delivery infrastructure restricts malicious downloads to Brazilian IP addresses and matching language and regional settings, serving legitimate software to other visitors. WhatsApp-based campaigns distribute ZIP attachments disguised as documents; after infection, Astaroth accesses WhatsApp Web, retrieves the victim's contacts, and automatically sends malicious messages to propagate through trusted relationships.
Astaroth establishes persistence through startup items and employs multiple defense-evasion techniques, including alternate data streams, hidden execution windows, script obfuscation, and process hollowing. It can create a legitimate process in a suspended state and replace its mapped contents with malicious code. JavaScript supports its functionality, including character-code-based deobfuscation that conceals execution commands. The malware also discovers running processes, checks for Avast antivirus, and collects local timestamps.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
TA2725 is a threat actor Proofpoint tracked since March 2022 that is known for using Brazilian banking malware (including Mispadu, Astaroth, and historically Grandoreiro) and credential phishing to target organizations mainly in Brazil, Mexico, and Spain.
...another set of attacks has led to the deployment of the Astaroth banking trojan. Sophos is tracking the second cluster under the moniker STAC3150 since September 24, 2025.
36 distinct techniques documented for this family, organized by ATT&CK tactic.
368 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
143 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Guildma, also referred to as Astaroth in the reference, is identified as the malware involved in an infection delivered through a Brazilian Portuguese-language email.
Guildma was delivered through a geofenced Brazilian Portuguese phishing email. A ZIP-delivered Windows shortcut fetched content into an NTFS alternate data stream, which was used to retrieve and install an AutoIt package; the resulting compiled AutoIt script established persistent Guildma malware on the Windows host.
Named as another Latin American banking trojan for comparison/background only.
A Brazilian banking trojan active since at least 2015 that uses layered infection chains, often beginning with Windows shortcut files and a downloader, to load its core payload in memory. In this report it is described as adding a WhatsApp Web spambot component that abuses an already authenticated victim session to harvest contacts and send malicious ZIP attachments in Portuguese to Brazilian numbers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.