September 16, 2019 By David Bisson 2 min read

The Astaroth Trojan used Facebook and YouTube profiles to support its infection chain in a new phishing campaign targeting Brazilian users.

First observed by Cofense, the phishing emails, which were written in Portuguese, masqueraded as one of three items: an invoice, a show ticket or a civil lawsuit notice. In each case, the email messages lured users into opening an .htm file to initiate the infection chain. Users who did so unknowingly downloaded a .ZIP archive that was geofenced to Brazil and contained a malicious .LNK file.

Upon running the .LNK file, the campaign downloaded JavaScript code from a Cloudflare Workers domain. The JavaScript snippet then pulled down multiple elements used to execute a sample of the Astaroth Trojan.

In this campaign, Astaroth used YouTube and Facebook profiles to host and maintain configuration data for its command-and-control (C&C) infrastructure. This information took the form of data contained within posts on a Facebook profile or within profile information for certain YouTube users. Through this technique, the attackers were able to bypass traditional security tools and collect sensitive data, such as financial information and stored passwords.

Astaroth’s Recent Activity

In September 2018, Cofense discovered a resurgence of Astaroth in which the Trojan potentially compromised as many as 8,000 machines in the span of one week. A few months later, Cybereason spotted a new variant of the malware abusing native operating system (OS) processes and exploiting security products to infect users in Brazil.

Then, in July, the Microsoft Defender ATP Research Team spotted a fileless malware campaign dropping Astaroth into memory.

How to Break an Infection Chain Initiated by Phishing

To help defend against infection chains initiated by phishing attacks, security teams should consider adopting a layered approach to email security that incorporates mail scanning, spam monitoring and other security measures. Companies should also practice ahead-of-threat detection to spot potentially malicious domains before they become active in phishing campaigns and other digital attacks.

More from

Generative AI security requires a solid framework

4 min read - How many companies intentionally refuse to use AI to get their work done faster and more efficiently? Probably none: the advantages of AI are too great to deny.The benefits AI models offer to organizations are undeniable, especially for optimizing critical operations and outputs. However, generative AI also comes with risk. According to the IBM Institute for Business Value, 96% of executives say adopting generative AI makes a security breach likely in their organization within the next three years.CISA Director Jen…

Q&A with Valentina Palmiotti, aka chompie

4 min read - The Pwn2Own computer hacking contest has been around since 2007, and during that time, there has never been a female to score a full win — until now.Valentina Palmiotti, aka chompie, changed that. At the March 2024 competition, Palmiotti scored a full win with her discovery of an Improper Update of Reference Count bug to escalate privileges on Windows 11. It was her first time entering Pwn2Own.Pwn2Own is considered one of the most — if not the most — prestigious…

Self-replicating Morris II worm targets AI email assistants

4 min read - The proliferation of generative artificial intelligence (gen AI) email assistants such as OpenAI’s GPT-3 and Google’s Smart Compose has revolutionized communication workflows. Unfortunately, it has also introduced novel attack vectors for cyber criminals. Leveraging recent advancements in AI and natural language processing, malicious actors can exploit vulnerabilities in gen AI systems to orchestrate sophisticated cyberattacks with far-reaching consequences. Recent studies have uncovered the insidious capabilities of self-replicating malware, exemplified by the “Morris II” strain created by researchers. How the Morris…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today