Researchers reported that the Guildma banking trojan, also tracked as Astaroth, continued targeting users in Brazil through large phishing campaigns delivering ZIP archives with malicious .LNK files disguised as invoices, payment proofs, tax notices, and COVID-19-themed messages. The malware focused heavily on stealing banking credentials—particularly from Brazilian institutions such as Banco do Brasil—while also harvesting browser, email, e-commerce, and streaming credentials, capturing screenshots and keystrokes, and enabling remote-control functions. Telemetry cited one major wave reaching up to 50,000 first-stage samples per day, underscoring the scale of the operation in Latin America.
Analysis showed a fast-evolving, multi-stage infection chain built for stealth and resilience. Guildma/Astaroth abused multiple Windows LOLBins including bitsadmin.exe, regsvr32, wmic, rundll32, certutil, explorer.exe, and Internet Explorer's ExtExport.exe, while newer variants also used the legacy finger.exe client over TCP/79 to fetch commands and a signed Microsoft Silverlight binary, coregen.exe, for Signed Binary Proxy Execution. The malware employed anti-debugging, anti-VM, and locale checks to restrict execution largely to Portuguese-language and Brazil-based systems, stored or loaded modules through obfuscated JScript and alternate data streams, and retrieved encrypted command-and-control infrastructure from YouTube channel descriptions with fallback servers to maintain access if primary infrastructure was disrupted.

Pull IOCs and campaign context straight into your stack.
13 events from the most recent confirmed update back to the earliest known activity.
On 2026-08-31, a Brazilian Portuguese phishing email infected a Windows lab host with Guildma/Astaroth through a delivery site restricted to Brazil-based IPs and Brazilian Portuguese/Brazil regional settings. The ZIP-delivered shortcut saved a DLL in an NTFS alternate data stream, which installed a persistent compiled AutoIt Guildma payload and communicated with an Azure Websites domain and two .cfd domains over HTTPS.
On 2022-08-19, SANS ISC documented an Astaroth/Guildma infection delivered through a Brazil-themed Boleto payment phishing email impersonating Grupo Solução & CIA and a fake DocuSign page serving a ZIP archive with LNK and CMD files. The infection established persistence via the Windows Startup folder, launched an AutoIt-based payload from C:\W45784602214, and exfiltrated data over HTTP POST to attacker-controlled domains.
ESET telemetry showed Guildma campaigns escalated into a massive operation in August 2019, reaching up to 50,000 first-stage samples per day. The campaign lasted almost two months and more than doubled detections seen in the prior 10 months.
Microsoft reported that Astaroth campaigns resumed in early February with a more evasive infection chain that hid payloads in Alternate Data Streams and abused Internet Explorer's ExtExport.exe to load malicious DLLs. The updated chain, first observed in late 2019, replaced earlier WMIC-related activity and continued targeting mainly users in Brazil via Portuguese-language phishing emails.
Cisco Talos observed thousands of phishing emails tied to Astaroth beginning in mid-2019, primarily targeting users in Brazil with Portuguese-language lures.
ESET reported that in late 2018, Guildma used WMIC with XSL files to download and execute JScript stages as part of its distribution chain.
McAfee uncovered an Astaroth banking-trojan campaign delivered through geo-restricted phishing links and ZIP/LNK files that used mshta.exe and AutoIt stages to load a Delphi payload. The malware used Ngrok endpoints for C2 and periodically retrieved GitHub-hosted images containing steganographically hidden configuration data; McAfee reported the malicious repositories to GitHub, which removed them.
SANS ISC reported a new Guildma/Astaroth campaign targeting South America, mainly Brazil, that used finger.exe to retrieve commands over TCP port 79 and abused Microsoft Silverlight's coregen.exe to load a malicious DLL.
Cisco Talos said recent Astaroth samples showed a particular emphasis on stealing banking information associated with Banco de Brasil customers.
Cisco Talos reported that later Astaroth phishing waves used COVID-19-related messages, including some impersonating Brazil's Ministry of Health, to deliver malicious ZIP archives.
ESET reported that after analyzing version 150, Guildma versions 151 and 152 were later released without substantial functional changes.
ESET reported that Guildma added a JScript dropper module in version 145 that attempted to disable UAC, weaken Windows security controls, and interfere with Diebold Warsaw protections.
ESET said Guildma introduced a new command-and-control retrieval method in version 142 by storing encrypted C2 data in YouTube channel descriptions. The operators also briefly tried Facebook before abandoning it.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 165 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
9 references tracked. Mallory keeps watching after this page renders.
isc.sans.edu
Open sourcemcafee.com
Open sourcemalpedia.caad.fkie.fraunhofer.de
Open sourcedeveloper.ibm.com
Open sourceisc.sans.edu
Open sourceisc.sans.edu
Open sourceblog.talosintelligence.com
Open sourcemicrosoft.com
Open sourcewelivesecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.