Boto-Cor-de-Rosa — Campaign Analysis & Threat Activity

Threat entity extracted from intelligence sources

Frequency
3
occurrences
First Seen
January 8, 2026
Last Seen
January 10, 2026

Boto-Cor-de-Rosa is a threat campaign tracked across 3 threat clusters and 3 intelligence report mentions on ThreatCluster. First observed January 8, 2026; most recent activity January 10, 2026.

Overview

Boto-Cor-de-Rosa is a threat campaign that uses WhatsApp as the delivery vector for the Astaroth Android banking trojan. The campaign signals a reemergence of Astaroth with a new distribution method, highlighting the risk of Android banking credential theft via WhatsApp-based social engineering aimed at users of bank-related services.

Related Threat Clusters

Recent Intelligence Reports

  • Astaroth Trojan Reemerges as Boto-Cor-de-Rosa, Spreads via WhatsApp in Brazil — Webpronews · January 10, 2026
  • Boto-Cor-de-Rosa campaign reveals Astaroth WhatsApp — Acronis · January 8, 2026
  • Astaroth banking malware returns with WhatsApp — Siliconangle · January 8, 2026

CVSS v3.1 Breakdown