Researchers detailed two major Brazil-linked banking malware operations, Guildma and Astaroth, both built to steal credentials, monitor victims, and facilitate online banking fraud. Guildma, active since at least 2015, evolved from a Brazil-focused banking trojan into a broader modular threat targeting more than 130 banks and 75 additional web services worldwide, while still concentrating overwhelmingly on Brazilian users. Avast said it blocked more than 155,000 infection attempts affecting over 26,000 users in 2019, with more than 98% of targeted users located in Brazil.
The malware families rely on stealthy infection chains and abuse of legitimate Windows components to evade detection. Guildma commonly arrives through phishing emails carrying ZIP archives and malicious .LNK files, then uses WMIC, XSL, and JavaScript downloaders to retrieve Delphi-based modules from changing infrastructure such as GitHub and Google Storage. Its toolset includes RAT functions, keylogging, screenshot capture, credential theft, process injection, browser and banking application monitoring, spam delivery, and bundled password-recovery utilities. Reporting on Astaroth similarly described information-stealing malware that hijacks legitimate OS and antivirus processes to harvest passwords and personal data, underscoring the continued sophistication of Brazilian banking malware campaigns.

Pull IOCs and campaign context straight into your stack.
6 events from the most recent confirmed update back to the earliest known activity.
Between January and July 2019, Avast reported protecting more than 26,000 users from 155,000 Guildma infection attempts, with more than 98% of targeted users located in Brazil.
In May 2019, Guildma expanded from primarily Brazilian targeting to a broader international scope, ultimately targeting more than 130 banks and 75 additional web services worldwide.
At the end of April 2019, Guildma operators introduced an obfuscated LNK variant that in some cases pointed download URLs to the TOR network.
Since September 2018, researchers observed more than 4,800 unique malicious Guildma LNK samples containing 280 hard-coded domains, showing sustained phishing-based distribution activity.
Avast's analysis states that Guildma had been active since at least 2015 as a modular banking trojan and spyware family primarily targeting Brazilian users and services.
Guildma operators briefly hosted version 139 payloads on a GitHub account named winsvrx, which GitHub removed after it was reported. The operators then shifted hosting to Google Storage buckets including ultramaker and later bradok.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 144 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.