CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Guildma (Astaroth) malware infection from Brazilian Portuguese email

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 5441

As cited

Copy frozen at (site build).

threat intel

Guildma (Astaroth) malware infection from Brazilian Portuguese email

A researcher deliberately infected a Windows lab host using a malicious Brazilian Portuguese email containing a geofenced link that delivered Guildma (Astaroth) malware only to Brazil-based IP addresses with Brazilian Portuguese language settings. The infection chain involved a zip archive with a Windows shortcut that retrieved a DLL via alternate data stream, which then installed a compiled AutoIt script for persistence. The analysis includes indicators of compromise such as email headers, file hashes, malicious domains, and network traffic patterns specific to this campaign.

Why it matters: Practitioners in Brazil or those protecting Brazilian-based users should monitor for geofenced Guildma campaigns using spoofed contract-related emails and the provided indicators to detect and block similar infection attempts in their environment.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Guildma (Astaroth) malware infection from Brazilian Portuguese email

A researcher deliberately infected a Windows lab host using a malicious Brazilian Portuguese email containing a geofenced link that delivered Guildma (Astaroth) malware only to Brazil-based IP addresses with Brazilian Portuguese language settings. The infection chain involved a zip archive with a Windows shortcut that retrieved a DLL via alternate data stream, which then installed a compiled AutoIt script for persistence. The analysis includes indicators of compromise such as email headers, file hashes, malicious domains, and network traffic patterns specific to this campaign.

Why it matters: Practitioners in Brazil or those protecting Brazilian-based users should monitor for geofenced Guildma campaigns using spoofed contract-related emails and the provided indicators to detect and block similar infection attempts in their environment.

VendorsMicrosoftGoogleGitHub
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary