Astaroth, also known as Guildma, is a modular Windows banking trojan of Brazilian origin active since at least 2015. It combines remote-access, spyware, credential-stealing, and banking-fraud functions, with campaigns primarily targeting Brazilian users and financial services before expanding to banks and online services across Latin America, Europe, and China. It has targeted browsers, banking applications, and other applications associated with online financial activity.
Astaroth is commonly distributed through phishing emails using invoice, tax, contract, invitation, and similar lures. Delivery chains have used malicious ZIP attachments containing LNK files, as well as VBS and HTML files, to execute staged downloaders and retrieve malware modules. Campaigns have also used geographic and locale filtering to limit payload delivery to Brazilian victims.
The malware uses a staged architecture comprising loaders, injectors, RAT components, banking modules, credential-stealing functionality, and a spam-mailing component. It can collect credentials and payment-card data, capture screenshots, log keystrokes, monitor targeted application windows, collect host metadata including external IP address and timestamps, and exfiltrate collected data to command-and-control infrastructure. Astaroth uses process hollowing to execute within legitimate processes and can establish persistence through startup mechanisms.
Astaroth employs multiple defense-evasion techniques, including NTFS alternate data streams for payload storage, hidden-window execution, JavaScript and JScript-based functionality, string obfuscation, Base64-encoded command-and-control data, anti-emulation checks, and abuse of regsvr32 for payload loading. Its core modules have historically been implemented in Delphi, while delivery and downloader stages have used scripting and compiled AutoIt components.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
TA2725 is a threat actor Proofpoint tracked since March 2022 that is known for using Brazilian banking malware (including Mispadu, Astaroth, and historically Grandoreiro) and credential phishing to target organizations mainly in Brazil, Mexico, and Spain.
...another set of attacks has led to the deployment of the Astaroth banking trojan. Sophos is tracking the second cluster under the moniker STAC3150 since September 24, 2025.
36 distinct techniques documented for this family, organized by ATT&CK tactic.
The campaign spreads via phishing emails posing as invoices, tax reports, invitations and similar types of messages containing a ZIP archive attachment with a malicious LNK file.
The LNK file opens a minimized Windows Management Instrumentation Command-line tool (wmic.exe) using the Command Shell (cmd.exe) to download and execute a next stage XSL file with a malicious payload.
The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
The malware authors have used large amounts of domains, various infection and stealing techniques, and programming languages (Delphi, JS, VBS,..) during Guildma’s long existence
has attempted to get victims to launch malicious Microsoft Word attachments delivered via spearphishing emails... has required user execution of a malicious MSI installer... has been executed through user installation of an executable disguised as a flash installer.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
The primary purpose of this module is to inject the GX module into one of the targeted files.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
The malicious JavaScript code is slightly obfuscated with the fromCharCode function or using public web-based obfuscators.
The primary purpose of this module is to inject the GX module into one of the targeted files.
The complex attack chain, which involves the use of multiple living-off-the-land binaries (LOLBins), results in the eventual loading of the Astaroth malware directly in memory. | The script then uses a LOLBin not previously seen in Astaroth attacks to load the first-stage malware code: ExtExport.exe, which is a legitimate utility shipped as part of Internet Explorer.
The first module (64) is executed using the regsrv32 tool, after all other modules are successfully downloaded.
The LNK file opens a minimized Windows Management Instrumentation Command-line tool (wmic.exe) using the Command Shell (cmd.exe) to download and execute a next stage XSL file with a malicious payload. (MITRE T1220 Squiblytwo Technique)
If a URL listed above is found or PuTTY is running, the module starts sniffing keys Enter , Backspace , Delete , Alt , Caps Lock , Ctrl
The second timer tries to access the content of the window and parse the HTML. The content is matched against various element IDs, element options, or expected inputs. If anything matches these rules, the corresponding data is extracted and immediately sent to the second-level C&C server.
Some of these components are credential-stealing plugins hidden inside the ADS stream of desktop.ini. Astaroth abuses these plugins to steal information from compromised systems: NirSoft’s MailPassView... NirSoft’s WebBrowserPassView... | NirSoft’s MailPassView – an email client password recovery tool
This step ends up with the process assigning high priority to itself and subsequently hiding the window... a file named trusted.certs ... is checked for a string called appj.bb.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all, netsh.exe, ifconfig, arp, route, nbtstat, and related APIs/commands to gather IP, MAC, DNS, DHCP, gateway, proxy, routing, ARP, and adapter information.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, sw_vers -productVersion, and fsutil.
The module checks for predefined, desktop email client related files and tries to steal saved contacts
The module also checks for installed software (antiviruses and “interesting” applications)
Adversaries may attempt to get a listing of security software, configurations, defensive tools, and sensors that are installed on a system or in a cloud environment.
If a URL listed above is found or PuTTY is running, the module starts sniffing keys Enter , Backspace , Delete , Alt , Caps Lock , Ctrl
The second timer tries to access the content of the window and parse the HTML. The content is matched against various element IDs, element options, or expected inputs. If anything matches these rules, the corresponding data is extracted and immediately sent to the second-level C&C server.
368 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
138 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Guildma was delivered through a geofenced Brazilian Portuguese phishing email. A ZIP-delivered Windows shortcut fetched content into an NTFS alternate data stream, which was used to retrieve and install an AutoIt package; the resulting compiled AutoIt script established persistent Guildma malware on the Windows host.
Named as another Latin American banking trojan for comparison/background only.
A Brazilian banking trojan active since at least 2015 that uses layered infection chains, often beginning with Windows shortcut files and a downloader, to load its core payload in memory. In this report it is described as adding a WhatsApp Web spambot component that abuses an already authenticated victim session to harvest contacts and send malicious ZIP attachments in Portuguese to Brazilian numbers.
Referenced only as related reading about a phishing kit tied to two-factor authentication theft; not part of the sextortion scam itself.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.