Broadcom Astaroth Banking Malware Campaign Targets Brazilian Users via WhatsApp
Article Content
Browse articles
The Astaroth banking malware has resurfaced, utilizing WhatsApp as an automated infection vector specifically targeting Brazilian users. This new campaign is referred to as 'Boto Cor-de-Rosa' and has been identified by the Acronis Threat Research Unit.
Ask AI about this cluster
Answers cite the sources they use
Updated 193d ago How this analysis works
More articles in this cluster (2)
Following this threat?
Track Astaroth in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Guildma (Astaroth) Malware Infection via Geofenced Brazilian Email On August 31, 2026, a Windows host was infected with Guildma (Astaroth) malware through a malicious email targeting Brazilian users. The email contained a geofenced link that delivered a ZIP archive with a Windows shortcut, which downloaded content into an alternate data stream in the Temp directory. The malware…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…