Guildma (Astaroth) Malware Infection via Geofenced Brazilian Email

Guildma (Astaroth) Malware Infection via Geofenced Brazilian Email

First seen 1 Sep 2026, 21:30 UTC Isc.Sans.Edumalpedia.caad.fkie.fraunhofer.deSocprime 66.5

Article Content

Browse articles
ThreatCluster

On August 31, 2026, a Windows host was infected with Guildma (Astaroth) malware through a malicious email targeting Brazilian users. The email contained a geofenced link that delivered a ZIP archive with a Windows shortcut, which downloaded content into an alternate data stream in the Temp directory. The malware utilized an AutoIt-based payload to establish persistence on the infected system. The attack was replicated in a lab environment, confirming the geofencing mechanism that restricts malware delivery based on language and regional settings. Analysts identified specific indicators of compromise (IOCs), including SHA-256 hashes for the downloaded files and the domains contacted by the malware. Organizations are advised to implement email filtering and monitor for suspicious activity related to .lnk files and alternate data streams. Immediate isolation of affected hosts is recommended to prevent further command and control communication.

Key Points: • Guildma malware targets Brazilian users through localized phishing emails. • The infection method involves a geofenced link delivering a ZIP archive with a malicious shortcut. • Organizations should monitor for specific IOCs and implement email filtering to mitigate risks.

Timeline

2026-08-31
Malware infection confirmed in lab
A Windows host was infected with Guildma malware via a geofenced link in a Brazilian Portuguese email.
Isc.Sans.Edu
2026-09-01
Socprime reports on Guildma infection
Socprime published an analysis detailing the infection method and persistence mechanisms of the Guildma malware.
Socprime