Astaroth Malware Spreads via WhatsApp to Steal Data
Key Takeaways Astaroth malware has evolved to use compromised WhatsApp Web sessions for propagation. The banking trojan exploits trust by sending malicious ZIP attachments to the victim’s...
Key Takeaways
- Astaroth malware has evolved to use compromised WhatsApp Web sessions for propagation.
- The banking trojan exploits trust by sending malicious ZIP attachments to the victim’s contacts.
- This new spambot component was identified by CrowdStrike in Q4 2025, primarily targeting users in Brazil.
- The malware leverages legitimate browser automation tools and operates in a hidden mode to evade detection.
- The campaign highlights a shift from traditional email phishing to more credible messaging platform attacks.
Astaroth, a persistent banking trojan, has adopted a novel and insidious method for propagation: hijacking WhatsApp Web sessions to distribute itself. This new tactic allows the malware to leverage a victim’s existing trust relationships, sending convincing messages and malicious attachments to their personal and professional contacts. This significantly increases the speed and efficacy of its spread, bypassing traditional email-based defenses.
Table Of Content
Previously, Astaroth campaigns predominantly relied on phishing emails and Windows shortcut files to initiate its multi-stage infection process. However, the introduction of a dedicated spambot component marks a strategic shift, enabling automated distribution directly through compromised WhatsApp Web accounts. This mechanism permits the malware to spread autonomously within a user’s network without direct attacker intervention for each message. Recipients are more likely to open attachments from known senders, drastically increasing the chances of successful infection.
CrowdStrike analysts first identified this new spambot component during the fourth quarter of 2025. They described it as a substantial escalation in Astaroth’s operational capabilities. In a report shared with Cyber Security News (CSN), CrowdStrike indicated that this activity is specifically concentrated in Brazil. Evidence for this geographic focus includes filtering for Brazilian phone numbers, the use of Portuguese-language messages, and browser settings configured to match local user preferences.
The inherent danger of this new approach lies in its ability to operate from a legitimate, active WhatsApp Web session rather than a newly created, suspicious account. This authentic source significantly lowers recipient suspicion, making the malware highly effective at expanding its infection footprint. This method echoes similar risks documented in reports concerning automated WhatsApp Web propagation, where trusted accounts were similarly exploited to broaden attack chains.
WhatsApp Account as Malware-Spreading Machine
Upon activation, the Astaroth spambot initiates a hidden browser session. It achieves this by utilizing WebDriver, a legitimate tool designed for browser automation. The malware then copies the victim’s existing browser profile, which may contain sensitive data such as session cookies and saved login credentials. Subsequently, it launches WhatsApp Web in a non-visible browser window.
The malware meticulously verifies that WhatsApp Web is fully loaded and that the victim is already authenticated before proceeding to harvest contacts. To maintain a focused campaign and avoid unnecessary exposure, it deliberately excludes various contact types, including groups, broadcast lists, linked devices, unsaved contacts, the victim’s own number, and any phone numbers outside of Brazil. This selective targeting suggests a calculated effort by the operators to concentrate on specific, high-value targets.
Before dispatching messages, Astaroth retrieves a ZIP payload from a pre-configured server. It then dynamically generates a Portuguese greeting based on the local time, attaches the malicious ZIP file, and sends a customized message to each selected contact. This sophisticated approach makes the malicious deliveries appear more organic and trustworthy than typical spam, mirroring the deceptive tactics observed in other WhatsApp malware distribution schemes.
The spambot further integrates WPPConnectWA-JS, a legitimate JavaScript library designed for interacting with WhatsApp Web functionalities. By weaponizing this otherwise innocuous tool, threat actors can effectively collect contact information and send messages through an authenticated account, eliminating the need for a separate, potentially traceable, fake profile. The component operates in a “headless” mode, meaning it runs without a visible user interface and removes typical browser indicators of automation. This stealthy operation makes the campaign exceptionally difficult for victims to detect as it runs silently in the background.
Evolving Brazilian Banking Threat
Astaroth has been an active threat since at least 2015, primarily known for its multi-layered infection chain targeting Brazilian users. Typically, a downloader, often delivered via a Windows shortcut file, fetches additional components that ultimately execute the core banking trojan directly in memory.
Researchers have noted significant code and design similarities between the Astaroth spambot and Vareg, another spambot previously associated with distributing Latin American banking trojans through WhatsApp. The shared functionalities, including contact filtering, message delivery logic, and timing controls, strongly suggest either a common developer behind both threats or a deliberate sharing of codebases.
This shift from email-based spam to leveraging messaging platforms like WhatsApp significantly enhances the credibility of each malicious lure. Brazilian banking trojan campaigns have consistently employed localized language, financial themes, and trusted communication channels to maximize their impact, a trend observed in various analyses of Brazilian banking trojan campaigns.
What You Should Do
- **Exercise Extreme Caution:** Treat all unexpected ZIP files, links, and commands with suspicion, even if they originate from known contacts. Verify the sender’s identity through an alternative communication channel before opening anything.
- **Limit WhatsApp Web Usage:** Organizations should restrict the use of WhatsApp Web to only essential business activities.
- **Monitor for Unusual Activity:** Implement monitoring for unusual WebDriver downloads, hidden browser sessions, and unexpected copies of browser profiles on company endpoints.
- **User Awareness Training:** Conduct regular user awareness training to educate employees about the dangers of social engineering, phishing, and malware spread via messaging applications.
- **Report Suspicious Messages:** Encourage prompt reporting of any suspicious WhatsApp messages or attachments to IT security teams.
- **Review WPPConnectWA-JS Downloads:** Monitor for downloads or usage of the WPPConnectWA-JS library if it is not a sanctioned tool for business operations.
- **Implement Browser Protections:** Utilize browser security features and extensions that can detect and prevent malicious downloads and automated browser activities.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.