Boto-Cor-de-Rosa is a threat campaign tracked across 3 threat clusters and 3 intelligence report mentions on ThreatCluster. First observed January 8, 2026; most recent activity January 10, 2026.
Boto-Cor-de-Rosa is a threat campaign that uses WhatsApp as the delivery vector for the Astaroth Android banking trojan. The campaign signals a reemergence of Astaroth with a new distribution method, highlighting the risk of Android banking credential theft via WhatsApp-based social engineering aimed at users of bank-related services.
Attackers have compromised Brazilian users through WhatsApp by distributing a malicious ZIP file containing a Visual Basic script that installs the Astaroth banking trojan. This campaign, named Boto-Cor-de-Rosa,…
The Astaroth banking trojan has resurfaced, now spreading through WhatsApp in Brazil under the name 'Boto-Cor-de-Rosa' or 'Pink Dolphin.' This campaign utilizes worm-like tactics to target users and steal financial…
The Astaroth banking malware has resurfaced, utilizing WhatsApp as an automated infection vector specifically targeting Brazilian users. This new campaign is referred to as 'Boto Cor-de-Rosa' and has been identified by…