Cybercriminals have evolved: the Astaroth banking trojan (also known as Guildma) is no longer spread through email but through an everyday messenger, WhatsApp. In a new STAC3150 report, Sophos reveals details of a campaign that began on September 24, 2025 and has already affected more than 250 users. Brazil has taken the main hit, but experts warn that the attack may spread to other regions. Here is how the scheme works and why it is more dangerous than before.
Attack Scheme: From View Once to Full Infection
The STAC3150 campaign relies heavily on social engineering. Attackers break into victims’ accounts via WhatsApp Web and send phishing messages to their contacts using the View Once option, creating an illusion of confidentiality. These messages contain a link to a ZIP archive with an important document, such as ORCAMENTO (budget) or COMPROVANTE (voucher). When the victim downloads the archive, the infection chain begins.
Inside the ZIP file is a malicious VBS or HTA file that launches PowerShell. The script downloads the second stage, an MSI installer that became part of the campaign in October 2025. It places files in Windows system directories such as %AppData%, adds itself to the registry for autorun, and activates a disguised AutoIt script masquerading as an innocent .log file. This script connects to a command and control server (manoelimoveiscaioba[.]com) and downloads the full Astaroth payload, designed for stealing banking data.
Astaroth is a classic banking trojan: it monitors the clipboard, intercepts clicks on financial websites, and steals credentials and session data. In this campaign, it has evolved further, using Selenium and WPPConnect to hijack WhatsApp sessions, steal contacts, and continue spreading spam. The pace of evolution is striking: within a month, file formats changed from VBS to MSI and even Python scripts.
Why Brazil and Why This Threatens the Rest of the World
Brazil is the epicenter, with 90 percent of attacks occurring there due to WhatsApp’s overwhelming popularity, used on more than 99 percent of smartphones, and generally weak cyber hygiene. The trojan targets local banks such as Banco do Brasil and Itaú, as well as cryptocurrency exchanges. But Sophos is seeing an increase in infections in Europe and the United States through international contact chains. Corporate networks are also at risk: a single compromised account can infect colleagues and lead to data leaks or financial losses.
How to Protect Yourself: Simple Steps from Sophos
Experts emphasize that the speed of the attack is key to its success. Here are the main recommendations:
In Short
The STAC3150 campaign uses WhatsApp to spread Astaroth through ZIP files containing MSI components and AutoIt scripts, enabling infection within minutes and allowing the theft of banking data and session information. Brazil is the main target for now, but global risks are rising. Protect yourself by avoiding suspicious archives, enabling two factor authentication, and using antivirus tools. As Sophos warns, it is better to be cautious than to lose your account.
month
week
day