Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
New SSH Bot Profiles Linux Systems Before Deploying Crypto Miner
July 31, 2026
DeepSeek-Powered Hermes Agent Autonomous Cyberattacks Target Exposed Servers
July 31, 2026
ShutterGap Flaw Exposes AWS Resources Between Security Scans
July 31, 2026
Home/Threats/Astaroth Malware Spreads via WhatsApp to Steal Data
Threats

Astaroth Malware Spreads via WhatsApp to Steal Data

Key Takeaways Astaroth malware has evolved to use compromised WhatsApp Web sessions for propagation. The banking trojan exploits trust by sending malicious ZIP attachments to the victim’s...

Jennifer sherman
Jennifer sherman
July 31, 2026 4 Min Read
4 0

Key Takeaways

  • Astaroth malware has evolved to use compromised WhatsApp Web sessions for propagation.
  • The banking trojan exploits trust by sending malicious ZIP attachments to the victim’s contacts.
  • This new spambot component was identified by CrowdStrike in Q4 2025, primarily targeting users in Brazil.
  • The malware leverages legitimate browser automation tools and operates in a hidden mode to evade detection.
  • The campaign highlights a shift from traditional email phishing to more credible messaging platform attacks.

Astaroth, a persistent banking trojan, has adopted a novel and insidious method for propagation: hijacking WhatsApp Web sessions to distribute itself. This new tactic allows the malware to leverage a victim’s existing trust relationships, sending convincing messages and malicious attachments to their personal and professional contacts. This significantly increases the speed and efficacy of its spread, bypassing traditional email-based defenses.

Table Of Content

  • Key Takeaways
  • WhatsApp Account as Malware-Spreading Machine
  • Evolving Brazilian Banking Threat
  • What You Should Do

Previously, Astaroth campaigns predominantly relied on phishing emails and Windows shortcut files to initiate its multi-stage infection process. However, the introduction of a dedicated spambot component marks a strategic shift, enabling automated distribution directly through compromised WhatsApp Web accounts. This mechanism permits the malware to spread autonomously within a user’s network without direct attacker intervention for each message. Recipients are more likely to open attachments from known senders, drastically increasing the chances of successful infection.

CrowdStrike analysts first identified this new spambot component during the fourth quarter of 2025. They described it as a substantial escalation in Astaroth’s operational capabilities. In a report shared with Cyber Security News (CSN), CrowdStrike indicated that this activity is specifically concentrated in Brazil. Evidence for this geographic focus includes filtering for Brazilian phone numbers, the use of Portuguese-language messages, and browser settings configured to match local user preferences.

The inherent danger of this new approach lies in its ability to operate from a legitimate, active WhatsApp Web session rather than a newly created, suspicious account. This authentic source significantly lowers recipient suspicion, making the malware highly effective at expanding its infection footprint. This method echoes similar risks documented in reports concerning automated WhatsApp Web propagation, where trusted accounts were similarly exploited to broaden attack chains.

WhatsApp Account as Malware-Spreading Machine

Upon activation, the Astaroth spambot initiates a hidden browser session. It achieves this by utilizing WebDriver, a legitimate tool designed for browser automation. The malware then copies the victim’s existing browser profile, which may contain sensitive data such as session cookies and saved login credentials. Subsequently, it launches WhatsApp Web in a non-visible browser window.

The malware meticulously verifies that WhatsApp Web is fully loaded and that the victim is already authenticated before proceeding to harvest contacts. To maintain a focused campaign and avoid unnecessary exposure, it deliberately excludes various contact types, including groups, broadcast lists, linked devices, unsaved contacts, the victim’s own number, and any phone numbers outside of Brazil. This selective targeting suggests a calculated effort by the operators to concentrate on specific, high-value targets.

Before dispatching messages, Astaroth retrieves a ZIP payload from a pre-configured server. It then dynamically generates a Portuguese greeting based on the local time, attaches the malicious ZIP file, and sends a customized message to each selected contact. This sophisticated approach makes the malicious deliveries appear more organic and trustworthy than typical spam, mirroring the deceptive tactics observed in other WhatsApp malware distribution schemes.

The spambot further integrates WPPConnectWA-JS, a legitimate JavaScript library designed for interacting with WhatsApp Web functionalities. By weaponizing this otherwise innocuous tool, threat actors can effectively collect contact information and send messages through an authenticated account, eliminating the need for a separate, potentially traceable, fake profile. The component operates in a “headless” mode, meaning it runs without a visible user interface and removes typical browser indicators of automation. This stealthy operation makes the campaign exceptionally difficult for victims to detect as it runs silently in the background.

Evolving Brazilian Banking Threat

Astaroth has been an active threat since at least 2015, primarily known for its multi-layered infection chain targeting Brazilian users. Typically, a downloader, often delivered via a Windows shortcut file, fetches additional components that ultimately execute the core banking trojan directly in memory.

Researchers have noted significant code and design similarities between the Astaroth spambot and Vareg, another spambot previously associated with distributing Latin American banking trojans through WhatsApp. The shared functionalities, including contact filtering, message delivery logic, and timing controls, strongly suggest either a common developer behind both threats or a deliberate sharing of codebases.

This shift from email-based spam to leveraging messaging platforms like WhatsApp significantly enhances the credibility of each malicious lure. Brazilian banking trojan campaigns have consistently employed localized language, financial themes, and trusted communication channels to maximize their impact, a trend observed in various analyses of Brazilian banking trojan campaigns.

What You Should Do

  • **Exercise Extreme Caution:** Treat all unexpected ZIP files, links, and commands with suspicion, even if they originate from known contacts. Verify the sender’s identity through an alternative communication channel before opening anything.
  • **Limit WhatsApp Web Usage:** Organizations should restrict the use of WhatsApp Web to only essential business activities.
  • **Monitor for Unusual Activity:** Implement monitoring for unusual WebDriver downloads, hidden browser sessions, and unexpected copies of browser profiles on company endpoints.
  • **User Awareness Training:** Conduct regular user awareness training to educate employees about the dangers of social engineering, phishing, and malware spread via messaging applications.
  • **Report Suspicious Messages:** Encourage prompt reporting of any suspicious WhatsApp messages or attachments to IT security teams.
  • **Review WPPConnectWA-JS Downloads:** Monitor for downloads or usage of the WPPConnectWA-JS library if it is not a sanctioned tool for business operations.
  • **Implement Browser Protections:** Utilize browser security features and extensions that can detect and prevent malicious downloads and automated browser activities.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitMalwarephishingSecurityThreat

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

CISA Warns Water Utilities: Remove Exposed PLCs From Public Internet

Next Post

Critical SolarWinds Web Help Desk Flaw (CVE-2024-28925) Bypasses SAML Login

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
CISA Warns Water Utilities: Remove Exposed PLCs From Public Internet
July 31, 2026
PHP Patches Critical SQL Injection, Memory Corruption Flaws
July 31, 2026
Gentlemen Ransomware Terminates 180 Security Processes Before Encryption
July 31, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us