{"id":9002,"date":"2025-11-22T19:03:30","date_gmt":"2025-11-22T19:03:30","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=9002"},"modified":"2025-11-22T19:03:30","modified_gmt":"2025-11-22T19:03:30","slug":"whatsapp-compromise-results-in-astaroth-deployment-sophos-information","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=9002","title":{"rendered":"WhatsApp compromise results in Astaroth deployment \u2013 Sophos Information"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p>Sophos analysts are investigating a persistent, multi-stage malware distribution marketing campaign concentrating on WhatsApp customers in Brazil. First noticed on September 24, 2025, the marketing campaign (tracked as STAC3150) delivers archive attachments containing a downloader script that retrieves a number of second-stage payloads. In early October, Counter Menace Unit\u2122 (CTU) researchers <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/news.sophos.com\/en-us\/2025\/10\/10\/whatsapp-worm-targets-brazilian-banking-customers\/\">detailed<\/a> exercise related to a separate Brazil-based marketing campaign wherein the menace actors leveraged WhatsApp to deploy the Maverick banking trojan for credential theft.<\/p>\n<p>In STAC3150, the second-stage payloads embrace a script that collects WhatsApp contact info and session information, and an installer that deploys the Astaroth (also called Guildma) banking trojan (see Determine 1).<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/11\/WhatsAppAstaroth2511-fig1.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-963730\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/11\/WhatsAppAstaroth2511-fig1.png\" alt=\"Diagram showing the STAC3150 attack chain that begins with WhatsApp phishing\" width=\"640\" height=\"204\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/11\/WhatsAppAstaroth2511-fig1.png 1240w, https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/11\/WhatsAppAstaroth2511-fig1.png?resize=300,96 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/11\/WhatsAppAstaroth2511-fig1.png?resize=768,245 768w, https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/11\/WhatsAppAstaroth2511-fig1.png?resize=1024,326 1024w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\"\/><\/a><em>Determine 1: Assault chain within the WhatsApp STAC3150 marketing campaign<\/em><\/p>\n<h3>Assault development<\/h3>\n<p>The assaults begin with a message that&#8217;s despatched utilizing the WhatsApp \u201cView As soon as\u201d choice (see Determine 2).<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/11\/WhatsAppAstaroth2511-fig2.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-963731\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/11\/WhatsAppAstaroth2511-fig2.png\" alt=\"WhatsApp lure in Portuguese, along with English translation\" width=\"640\" height=\"214\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/11\/WhatsAppAstaroth2511-fig2.png 1158w, https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/11\/WhatsAppAstaroth2511-fig2.png?resize=300,101 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/11\/WhatsAppAstaroth2511-fig2.png?resize=768,257 768w, https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/11\/WhatsAppAstaroth2511-fig2.png?resize=1024,343 1024w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\"\/><\/a><\/p>\n<p><em>Determine 2: WhatsApp lure (left) and translation (proper)<\/em><\/p>\n<p>The lure delivers a ZIP archive that accommodates a malicious VBS or HTA file. When executed, this malicious file launches PowerShell to retrieve second-stage payloads, together with a PowerShell or Python script that collects WhatsApp consumer information and, in later instances, an MSI installer that delivers the Astaroth malware. Determine 3 exhibits the modifications in downloader scripts and second-stage information over the course of the marketing campaign.<\/p>\n<p><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/11\/WhatsAppAstaroth2511-fig3.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-963725\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/11\/WhatsAppAstaroth2511-fig3.png\" alt=\"Changes in file formats used in STAC3150 campaign\" width=\"640\" height=\"254\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/11\/WhatsAppAstaroth2511-fig3.png 877w, https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/11\/WhatsAppAstaroth2511-fig3.png?resize=300,119 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/11\/WhatsAppAstaroth2511-fig3.png?resize=768,305 768w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\"\/><\/a><\/p>\n<p><em>Determine 3: File codecs used within the STAC3150 marketing campaign between September 24 and October 31, 2025<\/em><\/p>\n<p>In late September incidents, Sophos analysts noticed PowerShell getting used to retrieve the second-stage payloads through IMAP from an attacker-controlled e-mail account. In early October, the marketing campaign shifted to HTTP-based communication, leveraging PowerShell\u2019s Invoke-WebRequest command to contact a distant command and management (C2) server hosted on https: \/\/www . varegjopeaks . com (see Determine 4).<\/p>\n<p><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/11\/WhatsAppAstaroth2511-fig4.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-963726\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/11\/WhatsAppAstaroth2511-fig4.png\" alt=\"Display of PowerShell commands launched from malicious VBS file\" width=\"640\" height=\"79\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/11\/WhatsAppAstaroth2511-fig4.png 928w, https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/11\/WhatsAppAstaroth2511-fig4.png?resize=300,37 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/11\/WhatsAppAstaroth2511-fig4.png?resize=768,94 768w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\"\/><\/a><\/p>\n<p><em>Determine 4: First-stage PowerShell instructions launched from malicious VBS file<\/em><\/p>\n<p>The downloaded second-stage PowerShell or Python script (see Determine 5) makes use of the Selenium Chrome WebDriver and the WPPConnect JavaScript library to hijack WhatsApp Net classes, harvest contact info and session tokens, and facilitate spam distribution.<\/p>\n<p><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/11\/WhatsAppAstaroth2511-fig5.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-963727\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/11\/WhatsAppAstaroth2511-fig5.png\" alt=\"Extracts of PowerShell and Python scripts used to collect WhatsApp data\" width=\"640\" height=\"202\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/11\/WhatsAppAstaroth2511-fig5.png 1880w, https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/11\/WhatsAppAstaroth2511-fig5.png?resize=300,95 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/11\/WhatsAppAstaroth2511-fig5.png?resize=768,243 768w, https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/11\/WhatsAppAstaroth2511-fig5.png?resize=1024,324 1024w, https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/11\/WhatsAppAstaroth2511-fig5.png?resize=1536,485 1536w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\"\/><\/a><\/p>\n<p><em>Determine 5: PowerShell (left) and Python (proper) scripts for WhatsApp information assortment<\/em><\/p>\n<p>In late October, the second-stage information started to additionally embrace an MSI file (installer.msi) that delivers Astaroth malware. \u00a0The installer file writes information to disk and creates a startup registry key to take care of persistence. When executed, it launches the Astaroth malware through a malicious AutoIt script that masquerades as a .log file (see Determine 6). The malware communicates with a C2 server hosted at manoelimoveiscaioba . com.<\/p>\n<p><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/11\/WhatsAppAstaroth2511-fig6.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-963728\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/11\/WhatsAppAstaroth2511-fig6.png\" alt=\"AutoIT payload execution command\" width=\"640\" height=\"40\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/11\/WhatsAppAstaroth2511-fig6.png 884w, https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/11\/WhatsAppAstaroth2511-fig6.png?resize=300,19 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/11\/WhatsAppAstaroth2511-fig6.png?resize=768,48 768w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\"\/><\/a><\/p>\n<p><em>Determine 6: AutoIt payload execution<\/em><\/p>\n<h3>Victimology<\/h3>\n<p>Sophos analysts noticed this marketing campaign affecting greater than 250 prospects, with roughly 95% of the impacted gadgets situated in Brazil. The remaining have been situated in different Latin American international locations, the U.S., and Austria (see Determine 7).<\/p>\n<p><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/11\/WhatsAppAstaroth2511-fig7.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-963729\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/11\/WhatsAppAstaroth2511-fig7.png\" alt=\"Map showing locations of impacted Sophos customer devices\" width=\"640\" height=\"320\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/11\/WhatsAppAstaroth2511-fig7.png 2400w, https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/11\/WhatsAppAstaroth2511-fig7.png?resize=300,150 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/11\/WhatsAppAstaroth2511-fig7.png?resize=768,384 768w, https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/11\/WhatsAppAstaroth2511-fig7.png?resize=1024,512 1024w, https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/11\/WhatsAppAstaroth2511-fig7.png?resize=1536,768 1536w, https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/11\/WhatsAppAstaroth2511-fig7.png?resize=2048,1024 2048w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\"\/><\/a><\/p>\n<p><em>Determine 7: Distribution of Sophos buyer gadgets impacted by the WhatsApp marketing campaign deploying Astaroth between October 23 and October 28, 2025<\/em><\/p>\n<h3>Suggestions, detections, and indicators<\/h3>\n<p>Organizations ought to educate staff concerning the dangers of opening archive attachments despatched through social media and on the spot messaging platforms, even when obtained from identified contacts.<\/p>\n<p>SophosLabs has developed the countermeasures in Desk 1 to detect exercise related to this menace.<\/p>\n<table width=\"684\">\n<thead>\n<tr>\n<td width=\"325\">Title<\/td>\n<td width=\"359\">Description<\/td>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td width=\"325\">VBS\/DwnLdr-ADJT<\/td>\n<td width=\"359\">Detection for preliminary VBS file<\/td>\n<\/tr>\n<tr>\n<td width=\"325\">VBS\/DwnLdr-ADJW<\/td>\n<td width=\"359\">Detection for preliminary VBS file<\/td>\n<\/tr>\n<tr>\n<td width=\"325\">VBS\/DwnLdr-ADJS<\/td>\n<td width=\"359\">Detection for second-stage VBS file<\/td>\n<\/tr>\n<tr>\n<td width=\"325\">Troj\/Mdrop-KEP<\/td>\n<td width=\"359\">Detection for second-stage MSI file<\/td>\n<\/tr>\n<tr>\n<td width=\"325\">Troj\/Mdrop-KES<\/td>\n<td width=\"359\">Detection for second-stage MSI file<\/td>\n<\/tr>\n<tr>\n<td width=\"325\">Troj\/AutoIt-DJB<\/td>\n<td width=\"359\">Detection for AutoIt payload<\/td>\n<\/tr>\n<tr>\n<td width=\"325\">Troj\/HTADrp-CE<\/td>\n<td width=\"359\">Detection for HTA script<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><em>Desk 1: Sophos detections related to this menace<\/em><\/p>\n<p>The menace indicators in Desk 2 can be utilized to detect exercise associated to this menace. The domains might include malicious content material, so contemplate the dangers earlier than opening them in a browser.<\/p>\n<table width=\"684\">\n<thead>\n<tr>\n<td width=\"240\">Indicator<\/td>\n<td width=\"114\">Kind<\/td>\n<td width=\"330\">Context<\/td>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td width=\"240\">manoelimoveiscaioba[.]com<\/td>\n<td width=\"114\">Area identify<\/td>\n<td width=\"330\">C2 server utilized in WhatsApp STAC3150 marketing campaign<\/td>\n<\/tr>\n<tr>\n<td width=\"240\">varegjopeaks[.]com<\/td>\n<td width=\"114\">Area identify<\/td>\n<td width=\"330\">C2 server utilized in WhatsApp STAC3150 marketing campaign<\/td>\n<\/tr>\n<tr>\n<td width=\"240\">docsmoonstudioclayworks[.]on-line<\/td>\n<td width=\"114\">Area identify<\/td>\n<td width=\"330\">C2 server utilized in WhatsApp STAC3150 marketing campaign<\/td>\n<\/tr>\n<tr>\n<td width=\"240\">shopeeship[.]com<\/td>\n<td width=\"114\">Area identify<\/td>\n<td width=\"330\">C2 server utilized in WhatsApp STAC3150 marketing campaign<\/td>\n<\/tr>\n<tr>\n<td width=\"240\">miportuarios[.]com<\/td>\n<td width=\"114\">Area identify<\/td>\n<td width=\"330\">C2 server utilized in WhatsApp STAC3150 marketing campaign<\/td>\n<\/tr>\n<tr>\n<td width=\"240\">borizerefeicoes[.]com<\/td>\n<td width=\"114\">Area identify<\/td>\n<td width=\"330\">C2 server utilized in WhatsApp STAC3150 marketing campaign<\/td>\n<\/tr>\n<tr>\n<td width=\"240\">clhttradinglimited[.]com<\/td>\n<td width=\"114\">Area identify<\/td>\n<td width=\"330\">C2 server utilized in WhatsApp STAC3150 marketing campaign<\/td>\n<\/tr>\n<tr>\n<td width=\"240\">lefthandsuperstructures[.]com<\/td>\n<td width=\"114\">Area identify<\/td>\n<td width=\"330\">C2 server utilized in WhatsApp STAC3150 marketing campaign<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><em>Desk 2: Indicators for this menace<\/em><\/p>\n<\/p><\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>Sophos analysts are investigating a persistent, multi-stage malware distribution marketing campaign concentrating on WhatsApp customers in Brazil. First noticed on September 24, 2025, the marketing campaign (tracked as STAC3150) delivers archive attachments containing a downloader script that retrieves a number of second-stage payloads. In early October, Counter Menace Unit\u2122 (CTU) researchers detailed exercise related to [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":9004,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[6552,1429,309,5465,121,120,3262],"class_list":["post-9002","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-astaroth","tag-compromise","tag-deployment","tag-leads","tag-news","tag-sophos","tag-whatsapp"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/9002","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9002"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/9002\/revisions"}],"predecessor-version":[{"id":9003,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/9002\/revisions\/9003"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/9004"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9002"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9002"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9002"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-06-13 11:24:43 UTC -->