Socprime
Guildma (Astaroth) Malware Infection via Geofenced Brazilian Email
Article Content
On August 31, 2026, a Windows host was infected with Guildma (Astaroth) malware through a malicious email targeting Brazilian users. The email contained a geofenced link that delivered a ZIP archive with a Windows shortcut, which downloaded content into an alternate data stream in the Temp directory. The malware utilized an AutoIt-based payload to establish persistence on the infected system. The attack was replicated in a lab environment, confirming the geofencing mechanism that restricts malware delivery based on language and regional settings. Analysts identified specific indicators of compromise (IOCs), including SHA-256 hashes for the downloaded files and the domains contacted by the malware. Organizations are advised to implement email filtering and monitor for suspicious activity related to .lnk files and alternate data streams. Immediate isolation of affected hosts is recommended to prevent further command and control communication.
Key Points: • Guildma malware targets Brazilian users through localized phishing emails. • The infection method involves a geofenced link delivering a ZIP archive with a malicious shortcut. • Organizations should monitor for specific IOCs and implement email filtering to mitigate risks.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.