Astaroth
MITRE ATT&CK: S0373 View on attack.mitre.org
Aliases: Guildma, Astaroth
- First seen
- 2017-11-01 00:00:00
- Malware type
- trojan, credential-stealer
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 1846 (1524 malicious)
- Last IoC activity
- 2026-09-02 00:39:29
- Profile updated
- 2026-07-07 13:14:47
Targeted industries: financial-services government-and-public-sector
Targeted regions: country_code:br country_code:pt country_code:es
Context
Astaroth is a Trojan and information stealer known to affect companies in Europe, Brazil, and throughout Latin America. It has been known publicly since at least late 2017.
Recent IoC activity
1,529 malicious indicators in Maltiverse are attributed to Astaroth (S0373). The 20 most recently updated:
Detection coverage
- 540 Sigma rules
Malware & tools used
- System Time Discovery (attack-pattern)
- Hidden Window (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- Clipboard Data (attack-pattern)
- System Information Discovery (attack-pattern)
- System Checks (attack-pattern)
- Shared Modules (attack-pattern)
- Visual Basic (attack-pattern)
- Process Discovery (attack-pattern)
- Malicious File (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Standard Encoding (attack-pattern)
- Software Packing (attack-pattern)
- Regsvr32 (attack-pattern)
- Security Software Discovery (attack-pattern)
- Spearphishing Attachment (attack-pattern)
- Keylogging (attack-pattern)
- DLL (attack-pattern)
- JavaScript (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- XSL Script Processing (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Process Hollowing (attack-pattern)
- Shortcut Modification (attack-pattern)
- Windows Management Instrumentation (attack-pattern)
Reports & references
- Trend Micro — Water Makara Uses Obfuscated Javascript In Spear Phishing Campai (report)
- Cisco Talos — 2020 Year In Malware (report)
- blackberry.com — Report Bb 2021 Threat Report (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Astaroth (report)
- Microsoft — Dismantling A Fileless Campaign Microsoft Defender Atp Next Gen Protection Exposes Astaroth Attack (report)
- isc.sans.edu — 27482 (report)
- blog.easysol.net — Meet Lucifer International Trojan (report)
- botconf.eu — B2019 Soucek Hornak Demystifyingbankingtrojansfromlatinamerica (report)
- Microsoft — Latest Astaroth Living Off The Land Attacks Are Even More Invisible But Not Less Observable (report)
- isc.sans.edu — 28962 (report)
- armor.com — Astaroth Banking Trojan (report)
- github.com — 2022 01 17 Iocs For Astaroth Guildma Infection.Txt (report)
- cybereason.com — Information Stealing Malware Targeting Brazil Full Research (report)
- Cisco Talos — Astaroth Analysis (report)
- ESET — Guildma Devil Drives Electric (report)
- Kaspersky — 97779 (report)
- McAfee — Astaroth Banking Trojan Abusing Github For Resilience (report)
- labs.f-secure.com — Attack Detection Fundamentals Code Execution And Persistence Lab 1 (report)
- MITRE ATT&CK — S0373 (report)
- web.archive.org — Seeing Resurgence Demonic Astaroth Wmic Trojan (report)
- securityweek.com — Guildma Malware Expands Targets Beyond Brazil (report)
- securityweek.com — Extensive Living Land Hides Stealthy Malware Campaign (report)
- isc.sans.edu — 28962 (report)
- otx.alienvault.com — 6303804723Bccc7E3Caad737 (report)
External references
- mitre-attack — S0373
- Guildma
- Cofense Astaroth Sept 2018
- Securelist Brazilian Banking Malware July 2020
- Cybereason Astaroth Feb 2019
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy