Hackers spread Astaroth Trojan through WhatsApp: How to recognize and defend against ZIP traps

November 25, 2025  13:40

Cybercriminals have evolved: the Astaroth banking trojan (also known as Guildma) is no longer spread through email but through an everyday messenger, WhatsApp. In a new STAC3150 report, Sophos reveals details of a campaign that began on September 24, 2025 and has already affected more than 250 users. Brazil has taken the main hit, but experts warn that the attack may spread to other regions. Here is how the scheme works and why it is more dangerous than before.

Attack Scheme: From View Once to Full Infection

The STAC3150 campaign relies heavily on social engineering. Attackers break into victims’ accounts via WhatsApp Web and send phishing messages to their contacts using the View Once option, creating an illusion of confidentiality. These messages contain a link to a ZIP archive with an important document, such as ORCAMENTO (budget) or COMPROVANTE (voucher). When the victim downloads the archive, the infection chain begins.

Inside the ZIP file is a malicious VBS or HTA file that launches PowerShell. The script downloads the second stage, an MSI installer that became part of the campaign in October 2025. It places files in Windows system directories such as %AppData%, adds itself to the registry for autorun, and activates a disguised AutoIt script masquerading as an innocent .log file. This script connects to a command and control server (manoelimoveiscaioba[.]com) and downloads the full Astaroth payload, designed for stealing banking data.

Astaroth is a classic banking trojan: it monitors the clipboard, intercepts clicks on financial websites, and steals credentials and session data. In this campaign, it has evolved further, using Selenium and WPPConnect to hijack WhatsApp sessions, steal contacts, and continue spreading spam. The pace of evolution is striking: within a month, file formats changed from VBS to MSI and even Python scripts.

Why Brazil and Why This Threatens the Rest of the World

Brazil is the epicenter, with 90 percent of attacks occurring there due to WhatsApp’s overwhelming popularity, used on more than 99 percent of smartphones, and generally weak cyber hygiene. The trojan targets local banks such as Banco do Brasil and Itaú, as well as cryptocurrency exchanges. But Sophos is seeing an increase in infections in Europe and the United States through international contact chains. Corporate networks are also at risk: a single compromised account can infect colleagues and lead to data leaks or financial losses.

How to Protect Yourself: Simple Steps from Sophos

Experts emphasize that the speed of the attack is key to its success. Here are the main recommendations:

  • Never open ZIP files from unknown senders or even trusted contacts, especially if sent via View Once.
    • Enable two factor authentication in WhatsApp and monitor active WhatsApp Web sessions.
    • Use antivirus software with behavioral detection such as Sophos Intercept X or similar tools, which can catch PowerShell and MSI based attacks.
    • Keep Windows and WhatsApp updated, as patches close vulnerabilities related to the registry and autorun.
    • For businesses: segment the network and train employees to recognize phishing attempts.
    • If a file looks suspicious, upload it to VirusTotal before opening.

In Short

The STAC3150 campaign uses WhatsApp to spread Astaroth through ZIP files containing MSI components and AutoIt scripts, enabling infection within minutes and allowing the theft of banking data and session information. Brazil is the main target for now, but global risks are rising. Protect yourself by avoiding suspicious archives, enabling two factor authentication, and using antivirus tools. As Sophos warns, it is better to be cautious than to lose your account.


 
 
 
 
  • Archive