Boto Cor-de-Rosa — Campaign Analysis & Threat Activity

Threat entity extracted from intelligence sources

Frequency
2
occurrences
First Seen
January 9, 2026
Last Seen
January 9, 2026

Boto Cor-de-Rosa is a threat campaign that uses WhatsApp Web as a distribution channel to spread the Astaroth banking malware, employing automated messaging to the infected user's WhatsApp contacts to propagate.

Overview

Boto Cor-de-Rosa is a threat campaign that uses WhatsApp Web as a distribution channel to spread the Astaroth banking malware, employing automated messaging to the infected user's WhatsApp contacts to propagate. The campaign highlights a social-engineering based propagation tactic that targets Windows systems, increasing reach and speed of infection through a popular messaging platform.

Related Threat Clusters

  • Astaroth Banking Malware Campaign Targets Brazilian Users via WhatsApp

    The Astaroth banking malware has resurfaced, utilizing WhatsApp as an automated infection vector specifically targeting Brazilian users. This new campaign is referred to as 'Boto Cor-de-Rosa' and has been identified by…

    2 articles · Updated January 9, 2026
  • Astaroth Malware Targets Windows via WhatsApp Web in Brazil

    A new campaign named Boto Cor-de-Rosa has emerged, utilizing Astaroth banking malware to target Windows systems through WhatsApp Web. This malware automatically harvests contact lists and propagates itself to users in…

    2 articles · Updated January 9, 2026

Recent Intelligence Reports

  • Astaroth banking malware leverages WhatsApp Web for distribution — Broadcom · January 9, 2026
  • New Malware Automatically Send to Contacts via WhatsApp Web Attacks Windows Systems — Cybersecuritynews · January 9, 2026

CVSS v3.1 Breakdown