Astaroth

MITRE ATT&CK: S0373 View on attack.mitre.org

Aliases: Guildma, Astaroth

First seen
2017-11-01 00:00:00
Malware type
trojan, credential-stealer
Family
Malware family
Operating systems
windows
Related IoCs
1846 (1524 malicious)
Last IoC activity
2026-09-02 00:39:29
Profile updated
2026-07-07 13:14:47

Targeted industries: financial-services government-and-public-sector

Targeted regions: country_code:br country_code:pt country_code:es

Context

Astaroth is a Trojan and information stealer known to affect companies in Europe, Brazil, and throughout Latin America. It has been known publicly since at least late 2017.

Recent IoC activity

1,529 malicious indicators in Maltiverse are attributed to Astaroth (S0373). The 20 most recently updated:

TypeIndicatorUpdatedSources
hostname gleeful.top 2026-09-03 1
hostname dual.rest 2026-09-03 1
hostname tomografias.sbs 2026-09-02 1
hostname southamerica-east1-loyal-skill-365616.cloudfunctions.net 2026-09-02 2
hostname venturevision.online 2026-09-02 1
hostname screzintil560.nexuspatrimonial.city 2026-09-02 1
file sample cc44782356cb0effc528a7ab22c19ab360a55ebbbe01feb0967031aa191c5869 2026-09-02 1
file sample f62a958faf0491b2b2803be2ee69b664b58e4a1261f64e8530cdc1a3ff666aa4 2026-09-02 1
file sample a6044786991afdb9d42ceb350943987765a7d0e8537369b2092e3f019c0f63ca 2026-09-02 1
file sample 47d2908c4dd7f6f5eb4a8ef4306077b10315c44231f4bacd2bb811b245561911 2026-09-02 1
hostname crironminder210.supervisaoadministrativa.associates 2026-09-02 1
hostname fe-krrdbo6imq-uc.a.run.app 2026-09-02 1
hostname us-east4-vibrant-outpost-383916.cloudfunctions.net 2026-09-02 1
hostname etaluclac.sa.com 2026-09-02 1
hostname dreel.luminisconsultoria.io 2026-09-01 1
hostname frugonxil.elitefinancas.com 2026-08-31 1
hostname servicessolution.best 2026-08-28 1
hostname brutum.aurorainvestimentos.com 2026-08-28 1
hostname striranal67.coordenacaodeprojetos.io 2026-08-28 1
hostname croluncinal.coordenacaodeprojetos.io 2026-08-28 1

Detection coverage

  • 540 Sigma rules

Malware & tools used

  • System Time Discovery (attack-pattern)
  • Hidden Window (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Clipboard Data (attack-pattern)
  • System Information Discovery (attack-pattern)
  • System Checks (attack-pattern)
  • Shared Modules (attack-pattern)
  • Visual Basic (attack-pattern)
  • Process Discovery (attack-pattern)
  • Malicious File (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Standard Encoding (attack-pattern)
  • Software Packing (attack-pattern)
  • Regsvr32 (attack-pattern)
  • Security Software Discovery (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • Keylogging (attack-pattern)
  • DLL (attack-pattern)
  • JavaScript (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • XSL Script Processing (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Process Hollowing (attack-pattern)
  • Shortcut Modification (attack-pattern)
  • Windows Management Instrumentation (attack-pattern)

Reports & references

  • Trend Micro — Water Makara Uses Obfuscated Javascript In Spear Phishing Campai (report)
  • Cisco Talos — 2020 Year In Malware (report)
  • blackberry.com — Report Bb 2021 Threat Report (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Astaroth (report)
  • Microsoft — Dismantling A Fileless Campaign Microsoft Defender Atp Next Gen Protection Exposes Astaroth Attack (report)
  • isc.sans.edu — 27482 (report)
  • blog.easysol.net — Meet Lucifer International Trojan (report)
  • botconf.eu — B2019 Soucek Hornak Demystifyingbankingtrojansfromlatinamerica (report)
  • Microsoft — Latest Astaroth Living Off The Land Attacks Are Even More Invisible But Not Less Observable (report)
  • isc.sans.edu — 28962 (report)
  • armor.com — Astaroth Banking Trojan (report)
  • github.com — 2022 01 17 Iocs For Astaroth Guildma Infection.Txt (report)
  • cybereason.com — Information Stealing Malware Targeting Brazil Full Research (report)
  • Cisco Talos — Astaroth Analysis (report)
  • ESET — Guildma Devil Drives Electric (report)
  • Kaspersky — 97779 (report)
  • McAfee — Astaroth Banking Trojan Abusing Github For Resilience (report)
  • labs.f-secure.com — Attack Detection Fundamentals Code Execution And Persistence Lab 1 (report)
  • MITRE ATT&CK — S0373 (report)
  • web.archive.org — Seeing Resurgence Demonic Astaroth Wmic Trojan (report)
  • securityweek.com — Guildma Malware Expands Targets Beyond Brazil (report)
  • securityweek.com — Extensive Living Land Hides Stealthy Malware Campaign (report)
  • isc.sans.edu — 28962 (report)
  • otx.alienvault.com — 6303804723Bccc7E3Caad737 (report)

External references