CyberHappenings logo

Track cybersecurity events as they unfold. Sourced timelines. Filter, sort, and browse. Fast, privacy‑respecting. No invasive ads, no tracking.

Astaroth Banking Trojan Campaign Leverages GitHub for Resilience

First reported
Last updated
1 unique sources, 1 articles

Summary

Hide ▲

A new campaign distributing the Astaroth banking trojan uses GitHub to host malware configurations, allowing it to remain operational even after traditional command-and-control (C2) servers are taken down. The malware primarily targets users in Brazil and other Latin American countries. The infection chain starts with a phishing email containing a malicious Windows shortcut (.lnk) file, which downloads and executes the trojan. Astaroth monitors banking and cryptocurrency websites, steals credentials via keylogging, and uses steganography to hide configuration data within GitHub-hosted images. The malware also includes anti-analysis features to evade detection and persistence mechanisms to ensure it runs on reboot. The campaign has been active since at least July 2024, with previous attacks also targeting Brazil.

Timeline

  1. 13.10.2025 09:52 1 articles · 7h ago

    Astaroth Banking Trojan Campaign Leverages GitHub for Resilience

    A new campaign distributing the Astaroth banking trojan uses GitHub to host malware configurations, allowing it to remain operational even after traditional command-and-control (C2) servers are taken down. The malware primarily targets users in Brazil and other Latin American countries. The infection chain starts with a phishing email containing a malicious Windows shortcut (.lnk) file, which downloads and executes the trojan. Astaroth monitors banking and cryptocurrency websites, steals credentials via keylogging, and uses steganography to hide configuration data within GitHub-hosted images. The malware also includes anti-analysis features to evade detection and persistence mechanisms to ensure it runs on reboot. The campaign has been active since at least July 2024, with previous attacks also targeting Brazil.

    Show sources

Information Snippets