Acronis WhatsApp Exploit Used to Distribute Astaroth Banking Trojan in Brazil
Article Content
Browse articles
Attackers have compromised Brazilian users through WhatsApp by distributing a malicious ZIP file containing a Visual Basic script that installs the Astaroth banking trojan. This campaign, named Boto-Cor-de-Rosa, utilizes a Python-based propagation module and initiates the infection when victims open the disguised script within the ZIP archive.
Ask AI about this cluster
Answers cite the sources they use
Updated 193d ago How this analysis works
More articles in this cluster (2)
Following this threat?
Track Astaroth in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Guildma (Astaroth) Malware Infection via Geofenced Brazilian Email On August 31, 2026, a Windows host was infected with Guildma (Astaroth) malware through a malicious email targeting Brazilian users. The email contained a geofenced link that delivered a ZIP archive with a Windows shortcut, which downloaded content into an alternate data stream in the Temp directory. The malware…
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…