Astaroth (Guildma) Banking Trojan Uses Steganography and Ngrok Tunnels for C2 Resilience

Astaroth (Guildma) Banking Trojan Uses Steganography and (TL-2026-1738), also tracked as Guildma, is a high-severity malware campaign, first published 2026-07-28. It has no confirmed attribution, affects Microsoft Windows (desktop), maps to 32 MITRE ATT&CK techniques (T1016, T1027, T1041), and is covered by 9 detection rules and 30 indicators of compromise.

Key facts for TL-2026-1738

Threat ID
TL-2026-1738
Also known as
Guildma, Astaroth, STAC3150, Boto Cor-de-Rosa
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
2026-07-28
Last reviewed
2026-07-28
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
banking, finance, cryptocurrency, manufacturing, retail, government administration
Target regions
brazil, Latin America, mexico, uruguay, argentina, peru, colombia, venezuela, united states of america, austria
Detection rules
9
Indicators of compromise
30

Malware and tooling in Astaroth (Guildma) Banking Trojan Uses Steganography and

Malware and tooling: Astaroth, Troj/AutoIt-DJB, Troj/HTADrp-CE, Troj/Mdrop-KEP, Troj/Mdrop-KES, VBS/DwnLdr-ADJS, VBS/DwnLdr-ADJT, VBS/DwnLdr-ADJW, AutoIt, ngrok - S0508

Astaroth (aka Guildma), a Delphi-based Windows banking trojan active since 2015/2017 and targeting Brazil and Latin America, routes C2 traffic through Ngrok reverse-proxy tunnels and pulls fresh configuration every two hours from steganographic GitHub-hosted images to survive C2 takedowns. Recent STAC3150/"Boto Cor-de-Rosa" campaigns deliver it via WhatsApp "View Once" messages with a self-propagating Python worm module, while it steals banking/crypto credentials via a system-wide keyboard hook and self-destructs on English (US) locale or sandbox detection.

How Astaroth (Guildma) Banking Trojan Uses Steganography and works

Astaroth (also tracked as Guildma, MITRE ATT&CK software S0373) is a Delphi-written banking trojan and information stealer first reported in the wild circa 2015 and publicly documented since late 2017, primarily targeting Brazil (over 90% of infections) with secondary spread across Latin America (Mexico, Uruguay, Argentina, Peru, Colombia, Venezuela) and isolated hits in the United States and Austria.

Historically, Astaroth has been distributed via DocuSign-themed and government/HR-themed phishing emails containing geo-restricted ZIP archives with malicious LNK files. The LNK contains obfuscated JavaScript that fetches further JavaScript from hard-coded servers, which in turn drives an AutoIt loader that decodes shellcode to load a Delphi-based DLL, ultimately injected into RegSvcs.exe via process hollowing. Persistence is achieved by dropping the LNK into the Windows Startup folder or writing Registry Run keys. Two named 2024 distribution clusters — PINEAPPLE (abusing legitimate cloud services) and Water Makara (obfuscated JavaScript LNK loaders) — have been documented pushing Astaroth into Brazilian manufacturing, retail, and government-sector targets.

As of September 2025, a new campaign tracked by Sophos as STAC3150 (and by Acronis Threat Research Unit as "Boto Cor-de-Rosa") shifted the delivery vector to WhatsApp, abusing the "View Once" message feature to deliver ZIP archives containing malicious VBS or HTA files. Execution triggers PowerShell, which in early September 2025 retrieved second-stage payloads over IMAP from attacker-controlled email accounts, shifting to HTTP (PowerShell Invoke-WebRequest) by early October 2025. A PowerShell/Python script using Selenium Chrome WebDriver and the WPPConnect JavaScript library harvests the victim's WhatsApp contact list and session tokens; a newly added Python-based worm module then auto-forwards the malicious ZIP to every harvested contact, self-reporting delivery/failure/rate metrics in real time, giving the campaign worm-like self-propagation across WhatsApp's user base. By late October 2025, an MSI installer deploys the Astaroth payload itself via an AutoIt script masquerading as a .log file, establishing registry-based startup persistence. Sophos reported over 250 affected customers, ~95% located in Brazil.

For C2 resilience, Astaroth routes its custom binary-protocol traffic through Ngrok reverse-proxy tunnels to obscure the true operator-controlled server IP and bypass perimeter/firewall detection. When direct C2 contact is unavailable or infrastructure is taken down, the malware falls back to fetching configuration from images hosted on GitHub (and other public platforms, often reached via URL shorteners) with payload data appended after the image's EOF marker or hidden via steganographic encoding in pixel data — refreshed on a two-hour cycle so operators can restore control without needing victims to re-establish contact with primary C2.

Credential theft is performed via a SetWindowsHookExW WH_KEYBOARD_LL system-wide keyboard hook that polls the foreground browser window (Chrome, Firefox, IE/Edge) roughly once per second; keylogging activates only when a banking or cryptocurrency portal (e.g., caixa.gov.br, itau.com.br, santandernet.com.br, binance.com, metamask.io, bitcointrade.com.br) is detected in the active window, minimizing captured noise and analyst visibility.

Anti-analysis is extensive: nearly 1,000 internal strings are protected by a custom three-layer encoding scheme (XOR, byte reversal, session-key decoding); the malware enumerates and avoids running in the presence of debuggers (x32dbg, OllyDBG, IDA Pro, WinDbg), traffic analysis tools (Wireshark), virtualization indicators (QEMU-GA, VirtualBox), and SIEM/EDR agents (splunkd.exe); it fingerprints the volume serial number via GetVolumeInformationW; and — most notably — if the system locale resolves to English (United States), Astaroth treats the environment as a sandbox and triggers an automated system shutdown specifically to destroy forensic evidence rather than merely exiting.

No CVE applies — this is a malware/social-engineering delivery threat, not a software vulnerability. No single threat actor has been formally attributed across the full campaign lineage; PINEAPPLE, Water Makara, and the STAC3150 operators are tracked as distinct but overlapping distribution clusters, all financially motivated and Portuguese-language/Brazil-focused.

MITRE ATT&CK techniques used in TL-2026-1738

Discovery

T1016 System Network Configuration Discovery; T1057 Process Discovery; T1082 System Information Discovery; T1124 System Time Discovery; T1518 Software Discovery

Defense Evasion

T1027 Obfuscated Files or Information; T1055 Process Injection; T1140 Deobfuscate/Decode Files or Information; T1218 System Binary Proxy Execution; T1220 XSL Script Processing; T1497 Virtualization/Sandbox Evasion; T1564 Hide Artifacts; T1574 Hijack Execution Flow

Exfiltration

T1041 Exfiltration Over C2 Channel

Execution

T1047 Windows Management Instrumentation; T1059 Command and Scripting Interpreter; T1129 Shared Modules; T1204 User Execution

Collection

T1056 Input Capture; T1115 Clipboard Data

Command and Control

T1071 Application Layer Protocol; T1090 Proxy; T1102 Web Service; T1105 Ingress Tool Transfer; T1568 Dynamic Resolution

collection

T1074 Data Staged

command-and-control

T1132 Data Encoding

Credential Access

T1539 Steal Web Session Cookie; T1552 Unsecured Credentials; T1555 Credentials from Password Stores

Persistence

T1547 Boot or Logon Autostart Execution

Initial Access

T1566 Phishing

Affected products and versions in Astaroth (Guildma) Banking Trojan Uses Steganography and

  • Microsoft — Windows (desktop)
    Vulnerable versions: all currently supported desktop Windows versions
  • WhatsApp Inc. (Meta) — WhatsApp Messenger (View Once feature abused as delivery vector)
    Vulnerable versions: all versions supporting View Once media messages

Remediation for Astaroth (Guildma) Banking Trojan Uses Steganography and

Immediate actions

  • Block the identified STAC3150 C2 domains (manoelimoveiscaioba[.]com, varegjopeaks[.]com, docsmoonstudioclayworks[.]online, shopeeship[.]com, miportuarios[.]com, borizerefeicoes[.]com, clhttradinglimited[.]com, lefthandsuperstructures[.]com) at DNS/proxy/firewall
  • Block or closely inspect outbound Ngrok (*.ngrok.io / *.ngrok-free.app / *.ngrok.app) tunnel traffic on endpoints outside approved developer use
  • Alert on WhatsApp Desktop/Web session anomalies and mass outbound message bursts consistent with worm propagation
  • Deploy/enable Sophos or equivalent AV signatures for VBS/DwnLdr-ADJT, VBS/DwnLdr-ADJW, VBS/DwnLdr-ADJS, Troj/Mdrop-KEP, Troj/Mdrop-KES, Troj/AutoIt-DJB, Troj/HTADrp-CE
  • Quarantine and reset credentials for any endpoint observed executing an MSI installer following a WhatsApp-delivered ZIP/VBS/HTA chain

Workarounds

  • Restrict or monitor WhatsApp Desktop use on corporate endpoints in high-risk sectors (banking, retail, manufacturing, government) in Brazil/LatAm
  • Enforce non-English (US) locale detection is not a defense — instead alert on unexpected endpoint shutdowns immediately following execution of an unrecognized AutoIt/.log-named binary

Longer-term hardening

  • Deploy EDR with behavioral detection tuned to SetWindowsHookExW/WH_KEYBOARD_LL keyboard-hook installation combined with browser-process targeting
  • Restrict AutoIt script execution and unsigned/hollowed RegSvcs.exe process injection via application control (WDAC/AppLocker)
  • User awareness training on WhatsApp 'View Once' ZIP lures and DocuSign-themed phishing specific to Brazilian/LatAm financial-sector staff
  • Egress filtering / TLS inspection to detect anomalous image downloads from GitHub followed by non-image binary parsing on endpoints

Timeline of Astaroth (Guildma) Banking Trojan Uses Steganography and

  • Astaroth (Guildma) banking trojan first detected in the wild, targeting Latin American banking and cryptocurrency users.
  • Astaroth becomes publicly documented as a distinct malware family, later catalogued by MITRE ATT&CK as software S0373.
  • The PINEAPPLE threat cluster is observed abusing legitimate cloud services to distribute Astaroth to Brazilian users via phishing.
  • The Water Makara threat cluster resurfaces Astaroth via DocuSign-themed spear-phishing emails with obfuscated JavaScript LNK loaders, targeting Brazilian manufacturing, retail, and government organizations.
  • Early STAC3150 second-stage payload delivery uses IMAP-based retrieval from attacker-controlled email accounts.
  • Sophos begins tracking STAC3150, a campaign abusing WhatsApp 'View Once' messages to deliver ZIP archives containing malicious VBS/HTA files.
  • STAC3150 second-stage payload retrieval shifts from IMAP to HTTP via PowerShell's Invoke-WebRequest.
  • McAfee and other researchers publicly report Astaroth abusing GitHub-hosted steganographic images to fetch resilient C2 configuration updates after infrastructure takedowns.
  • By late October 2025, STAC3150 deploys an MSI installer that launches the Astaroth payload via an AutoIt script masquerading as a .log file, establishing registry-based startup persistence.
  • Sophos publishes a technical analysis of the STAC3150 WhatsApp-to-Astaroth campaign, reporting over 250 affected customers, approximately 95% located in Brazil.
  • Reporting citing Acronis Threat Research Unit's 'Boto Cor-de-Rosa' analysis reveals a new Python-based worm module that harvests WhatsApp contacts and auto-forwards malicious ZIP archives, giving the campaign self-propagating, worm-like spread.
  • Picus Security publishes an analysis of Astaroth's Ngrok-tunneled C2, two-hour steganographic configuration refresh cycle, keyboard-hook credential theft, and locale/sandbox-triggered self-destruction behavior.

Sources cited for Astaroth (Guildma) Banking Trojan Uses Steganography and

Threats related to Astaroth (Guildma) Banking Trojan Uses Steganography and

Detection coverage for TL-2026-1738

As of 2026-07-28, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1738 across Splunk SPL, Microsoft KQL and Sigma, covering 30 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Community OSINT corroboration for TL-2026-1738

2 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats