Astaroth operators have expanded their banking trojan's delivery methods by leveraging WhatsApp Web to automatically send malicious ZIP files to victims' trusted contacts This article explores methods leveraging whatsapp. . This newly identified capability turns an infected user's WhatsApp account into a spam distribution channel, increasing the credibility and reach of Astaroth campaigns targeting Brazil.

Astaroth, also known as Guildma, has been active since at least 201520152015, relying on email spam and multi-stage infection chains to target victims. A hidden component stealthily connects to an unsuspecting victim's active WhatsApp Web session, gathering contacts and delivering personalized messages via ZIP attachments. The campaign primarily targets Brazil, with researchers finding Portuguese-language message templates, targeted phone number filters for Brazilians, and browser request headers configured for Portuguese-speaking users.

It employs advanced string obfuscation techniques previously used in Astaroth samples, indicating the feature was developed by existing operators rather than acquired from external sources. After validation, the configuration includes essential operational settings such as enabling the bot, message delays, greeting templates, text content, ZIP payload URLs, and a flag for headless browser mode. It then copies the User Data profile directory from this browser into a folder like C:\Users\Public\Temp\ChromeAuto_.