The Astaroth banking trojan has added a spambot component that hijacks victims’ active WhatsApp Web sessions to distribute malicious ZIP attachments, with activity primarily targeting users in Brazil. According to CrowdStrike, the malware launches a headless Chromium or Microsoft Edge browser through WebDriver, suppresses automation indicators, checks whether the victim is already logged in to WhatsApp Web, and then uses the legitimate WPPConnect/WA-JS library to enumerate contacts and send messages that appear to come from the victim’s own account.
The spambot is designed to maximize delivery while reducing suspicion, filtering out groups, broadcasts, linked devices, unsaved contacts, the victim’s own account, and non-Brazilian phone numbers, while tailoring Portuguese greetings by time of day before sending lures. CrowdStrike also found substantial code and configuration overlap with the earlier Vareg spambot—including nearly identical contact filtering, message delivery logic, and delay behavior—indicating likely code sharing or a common developer; researchers published detection guidance, a YARA rule, and related filesystem, telemetry, hash, and domain indicators tied to the campaign.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
On 2026-06-07, CrowdStrike published technical analysis of Astaroth's new spambot component, describing its use of headless browsers, WhatsApp Web session abuse, and the WA-JS/WPPConnect library to send malicious ZIP attachments to Brazil-based contacts. The report also documented code overlap with the earlier Vareg spambot and provided detection guidance, indicators, and a YARA rule.
CrowdStrike reported that Astaroth started distributing its own spambot component in Q4 2025 to abuse victims' WhatsApp Web sessions for malware delivery. The report notes this activity emerged around the time earlier Vareg spambot activity ceased.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 14 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.