Astaroth (Guildma) Banking Trojan Uses Steganography and Ngrok Tunnels for C2 Resilience
Astaroth (Guildma) Banking Trojan Uses Steganography and (TL-2026-1738), also tracked as Guildma, is a high-severity malware campaign, first published 2026-07-28. It has no confirmed attribution, affects Microsoft Windows (desktop), maps to 32 MITRE ATT&CK techniques (T1016, T1027, T1041), and is covered by 9 detection rules and 30 indicators of compromise.
Key facts for TL-2026-1738
- Threat ID
- TL-2026-1738
- Also known as
- Guildma, Astaroth, STAC3150, Boto Cor-de-Rosa
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-07-28
- Last reviewed
- 2026-07-28
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- banking, finance, cryptocurrency, manufacturing, retail, government administration
- Target regions
- brazil, Latin America, mexico, uruguay, argentina, peru, colombia, venezuela, united states of america, austria
- Detection rules
- 9
- Indicators of compromise
- 30
Malware and tooling in Astaroth (Guildma) Banking Trojan Uses Steganography and
Malware and tooling: Astaroth, Troj/AutoIt-DJB, Troj/HTADrp-CE, Troj/Mdrop-KEP, Troj/Mdrop-KES, VBS/DwnLdr-ADJS, VBS/DwnLdr-ADJT, VBS/DwnLdr-ADJW, AutoIt, ngrok - S0508
Astaroth (aka Guildma), a Delphi-based Windows banking trojan active since 2015/2017 and targeting Brazil and Latin America, routes C2 traffic through Ngrok reverse-proxy tunnels and pulls fresh configuration every two hours from steganographic GitHub-hosted images to survive C2 takedowns. Recent STAC3150/"Boto Cor-de-Rosa" campaigns deliver it via WhatsApp "View Once" messages with a self-propagating Python worm module, while it steals banking/crypto credentials via a system-wide keyboard hook and self-destructs on English (US) locale or sandbox detection.
How Astaroth (Guildma) Banking Trojan Uses Steganography and works
Astaroth (also tracked as Guildma, MITRE ATT&CK software S0373) is a Delphi-written banking trojan and information stealer first reported in the wild circa 2015 and publicly documented since late 2017, primarily targeting Brazil (over 90% of infections) with secondary spread across Latin America (Mexico, Uruguay, Argentina, Peru, Colombia, Venezuela) and isolated hits in the United States and Austria.
Historically, Astaroth has been distributed via DocuSign-themed and government/HR-themed phishing emails containing geo-restricted ZIP archives with malicious LNK files. The LNK contains obfuscated JavaScript that fetches further JavaScript from hard-coded servers, which in turn drives an AutoIt loader that decodes shellcode to load a Delphi-based DLL, ultimately injected into RegSvcs.exe via process hollowing. Persistence is achieved by dropping the LNK into the Windows Startup folder or writing Registry Run keys. Two named 2024 distribution clusters — PINEAPPLE (abusing legitimate cloud services) and Water Makara (obfuscated JavaScript LNK loaders) — have been documented pushing Astaroth into Brazilian manufacturing, retail, and government-sector targets.
As of September 2025, a new campaign tracked by Sophos as STAC3150 (and by Acronis Threat Research Unit as "Boto Cor-de-Rosa") shifted the delivery vector to WhatsApp, abusing the "View Once" message feature to deliver ZIP archives containing malicious VBS or HTA files. Execution triggers PowerShell, which in early September 2025 retrieved second-stage payloads over IMAP from attacker-controlled email accounts, shifting to HTTP (PowerShell Invoke-WebRequest) by early October 2025. A PowerShell/Python script using Selenium Chrome WebDriver and the WPPConnect JavaScript library harvests the victim's WhatsApp contact list and session tokens; a newly added Python-based worm module then auto-forwards the malicious ZIP to every harvested contact, self-reporting delivery/failure/rate metrics in real time, giving the campaign worm-like self-propagation across WhatsApp's user base. By late October 2025, an MSI installer deploys the Astaroth payload itself via an AutoIt script masquerading as a .log file, establishing registry-based startup persistence. Sophos reported over 250 affected customers, ~95% located in Brazil.
For C2 resilience, Astaroth routes its custom binary-protocol traffic through Ngrok reverse-proxy tunnels to obscure the true operator-controlled server IP and bypass perimeter/firewall detection. When direct C2 contact is unavailable or infrastructure is taken down, the malware falls back to fetching configuration from images hosted on GitHub (and other public platforms, often reached via URL shorteners) with payload data appended after the image's EOF marker or hidden via steganographic encoding in pixel data — refreshed on a two-hour cycle so operators can restore control without needing victims to re-establish contact with primary C2.
Credential theft is performed via a SetWindowsHookExW WH_KEYBOARD_LL system-wide keyboard hook that polls the foreground browser window (Chrome, Firefox, IE/Edge) roughly once per second; keylogging activates only when a banking or cryptocurrency portal (e.g., caixa.gov.br, itau.com.br, santandernet.com.br, binance.com, metamask.io, bitcointrade.com.br) is detected in the active window, minimizing captured noise and analyst visibility.
Anti-analysis is extensive: nearly 1,000 internal strings are protected by a custom three-layer encoding scheme (XOR, byte reversal, session-key decoding); the malware enumerates and avoids running in the presence of debuggers (x32dbg, OllyDBG, IDA Pro, WinDbg), traffic analysis tools (Wireshark), virtualization indicators (QEMU-GA, VirtualBox), and SIEM/EDR agents (splunkd.exe); it fingerprints the volume serial number via GetVolumeInformationW; and — most notably — if the system locale resolves to English (United States), Astaroth treats the environment as a sandbox and triggers an automated system shutdown specifically to destroy forensic evidence rather than merely exiting.
No CVE applies — this is a malware/social-engineering delivery threat, not a software vulnerability. No single threat actor has been formally attributed across the full campaign lineage; PINEAPPLE, Water Makara, and the STAC3150 operators are tracked as distinct but overlapping distribution clusters, all financially motivated and Portuguese-language/Brazil-focused.
MITRE ATT&CK techniques used in TL-2026-1738
Discovery
T1016 System Network Configuration Discovery; T1057 Process Discovery; T1082 System Information Discovery; T1124 System Time Discovery; T1518 Software Discovery
Defense Evasion
T1027 Obfuscated Files or Information; T1055 Process Injection; T1140 Deobfuscate/Decode Files or Information; T1218 System Binary Proxy Execution; T1220 XSL Script Processing; T1497 Virtualization/Sandbox Evasion; T1564 Hide Artifacts; T1574 Hijack Execution Flow
Exfiltration
T1041 Exfiltration Over C2 Channel
Execution
T1047 Windows Management Instrumentation; T1059 Command and Scripting Interpreter; T1129 Shared Modules; T1204 User Execution
Collection
T1056 Input Capture; T1115 Clipboard Data
Command and Control
T1071 Application Layer Protocol; T1090 Proxy; T1102 Web Service; T1105 Ingress Tool Transfer; T1568 Dynamic Resolution
collection
command-and-control
Credential Access
T1539 Steal Web Session Cookie; T1552 Unsecured Credentials; T1555 Credentials from Password Stores
Persistence
T1547 Boot or Logon Autostart Execution
Initial Access
Affected products and versions in Astaroth (Guildma) Banking Trojan Uses Steganography and
- Microsoft — Windows (desktop)
Vulnerable versions: all currently supported desktop Windows versions - WhatsApp Inc. (Meta) — WhatsApp Messenger (View Once feature abused as delivery vector)
Vulnerable versions: all versions supporting View Once media messages
Remediation for Astaroth (Guildma) Banking Trojan Uses Steganography and
Immediate actions
- Block the identified STAC3150 C2 domains (manoelimoveiscaioba[.]com, varegjopeaks[.]com, docsmoonstudioclayworks[.]online, shopeeship[.]com, miportuarios[.]com, borizerefeicoes[.]com, clhttradinglimited[.]com, lefthandsuperstructures[.]com) at DNS/proxy/firewall
- Block or closely inspect outbound Ngrok (*.ngrok.io / *.ngrok-free.app / *.ngrok.app) tunnel traffic on endpoints outside approved developer use
- Alert on WhatsApp Desktop/Web session anomalies and mass outbound message bursts consistent with worm propagation
- Deploy/enable Sophos or equivalent AV signatures for VBS/DwnLdr-ADJT, VBS/DwnLdr-ADJW, VBS/DwnLdr-ADJS, Troj/Mdrop-KEP, Troj/Mdrop-KES, Troj/AutoIt-DJB, Troj/HTADrp-CE
- Quarantine and reset credentials for any endpoint observed executing an MSI installer following a WhatsApp-delivered ZIP/VBS/HTA chain
Workarounds
- Restrict or monitor WhatsApp Desktop use on corporate endpoints in high-risk sectors (banking, retail, manufacturing, government) in Brazil/LatAm
- Enforce non-English (US) locale detection is not a defense — instead alert on unexpected endpoint shutdowns immediately following execution of an unrecognized AutoIt/.log-named binary
Longer-term hardening
- Deploy EDR with behavioral detection tuned to SetWindowsHookExW/WH_KEYBOARD_LL keyboard-hook installation combined with browser-process targeting
- Restrict AutoIt script execution and unsigned/hollowed RegSvcs.exe process injection via application control (WDAC/AppLocker)
- User awareness training on WhatsApp 'View Once' ZIP lures and DocuSign-themed phishing specific to Brazilian/LatAm financial-sector staff
- Egress filtering / TLS inspection to detect anomalous image downloads from GitHub followed by non-image binary parsing on endpoints
Timeline of Astaroth (Guildma) Banking Trojan Uses Steganography and
- Astaroth (Guildma) banking trojan first detected in the wild, targeting Latin American banking and cryptocurrency users.
- Astaroth becomes publicly documented as a distinct malware family, later catalogued by MITRE ATT&CK as software S0373.
- The PINEAPPLE threat cluster is observed abusing legitimate cloud services to distribute Astaroth to Brazilian users via phishing.
- The Water Makara threat cluster resurfaces Astaroth via DocuSign-themed spear-phishing emails with obfuscated JavaScript LNK loaders, targeting Brazilian manufacturing, retail, and government organizations.
- Early STAC3150 second-stage payload delivery uses IMAP-based retrieval from attacker-controlled email accounts.
- Sophos begins tracking STAC3150, a campaign abusing WhatsApp 'View Once' messages to deliver ZIP archives containing malicious VBS/HTA files.
- STAC3150 second-stage payload retrieval shifts from IMAP to HTTP via PowerShell's Invoke-WebRequest.
- McAfee and other researchers publicly report Astaroth abusing GitHub-hosted steganographic images to fetch resilient C2 configuration updates after infrastructure takedowns.
- By late October 2025, STAC3150 deploys an MSI installer that launches the Astaroth payload via an AutoIt script masquerading as a .log file, establishing registry-based startup persistence.
- Sophos publishes a technical analysis of the STAC3150 WhatsApp-to-Astaroth campaign, reporting over 250 affected customers, approximately 95% located in Brazil.
- Reporting citing Acronis Threat Research Unit's 'Boto Cor-de-Rosa' analysis reveals a new Python-based worm module that harvests WhatsApp contacts and auto-forwards malicious ZIP archives, giving the campaign self-propagating, worm-like spread.
- Picus Security publishes an analysis of Astaroth's Ngrok-tunneled C2, two-hour steganographic configuration refresh cycle, keyboard-hook credential theft, and locale/sandbox-triggered self-destruction behavior.
Sources cited for Astaroth (Guildma) Banking Trojan Uses Steganography and
- Astaroth (Guildma) Uses Steganography and Ngrok for C2 Resilience
- WhatsApp Compromise Leads to Astaroth Deployment
- Astaroth: Banking Trojan Abusing GitHub for Resilience
- Astaroth Banking Trojan Abuses GitHub to Remain Operational After Takedowns
- WhatsApp Worm Spreads Astaroth Banking Trojan Across Brazil via Contact Auto-Messaging
- Astaroth unleashed (Boto Cor-de-Rosa campaign analysis)
- Astaroth, Software S0373
- Astaroth (Malware Family)
- Guildma is now using Finger and Signed Binary Proxy Execution to evade defenses
Threats related to Astaroth (Guildma) Banking Trojan Uses Steganography and
- Astaroth (Guildma) Banking Trojan Adds WhatsApp Web Spambot Module — STAC3150 / "Boto Cor-de-Rosa" Campaign Self-Propagates Across Brazil
- Remcos RAT Delivered via Steganographic Multi-Stage Loader in 'GST Debit Note' India-Targeted Phishing Campaign
- APT28 (Fancy Bear) Deploys BadPaw Loader and MeowMeow Backdoor Targeting Ukrainian Critical Infrastructure
- Nimbus RAT: Java-based Remote Access Trojan Delivered via Microsoft Teams Vishing, Quick Assist, and Google Drive C2
Detection coverage for TL-2026-1738
As of 2026-07-28, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1738 across Splunk SPL, Microsoft KQL and Sigma, covering 30 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-1738
2 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.