Skip to content
Malware

Astaroth Malware Turns Your WhatsApp Account Into a Malware-Spreading Machine

Astaroth has added a new way to spread, turning a victim’s WhatsApp Web session into a delivery channel for the same malware. The banking trojan sends convincing messages and a malicious ZIP attachment to people in the user’s own contact list, exploiting trust in familiar senders. This gives attacke...

· Jul 31, 2026 · 5 min read · 👁 1 views
Astaroth Malware Turns Your WhatsApp Account Into a Malware-Spreading Machine

Astaroth has added a new way to spread, turning a victim’s WhatsApp Web session into a delivery channel for the same malware.

The banking trojan sends convincing messages and a malicious ZIP attachment to people in the user’s own contact list, exploiting trust in familiar senders. This gives attackers a faster route into personal and business conversations.

Earlier campaigns relied mainly on phishing emails and shortcut files that launched a hidden infection chain on Windows.

The new component shifts delivery to WhatsApp Web, allowing the operation to move from one compromised account to many contacts without the attacker writing every message.

For recipients, the familiar sender can lower suspicion and raise the odds that they open the attachment.

CrowdStrike analysts identified the new spambot component in the fourth quarter of 2025, describing it as a significant expansion of Astaroth’s operations.

CrowdStrike said in a report shared with Cyber Security News (CSN) that the activity is focused on Brazil, with filtering for Brazilian phone numbers, Portuguese-language messages, and browser settings that match local users.

The threat matters because Astaroth is not simply sending spam from a fake account. It uses a legitimate session already connected to WhatsApp Web and automatically reaches people who may know the victim.

Similar risks were documented in this report on automated WhatsApp Web propagation, where trusted accounts were also abused to widen an infection chain.

WhatsApp Account as Malware-Spreading Machine

Once active, the spambot creates a hidden browser session through WebDriver, a legitimate browser automation tool.

It copies the victim’s browser profile, which can include session cookies and saved information, then opens WhatsApp Web without displaying a visible browser window.

Astaroth infection chain (Source - CrowdStrike)
Astaroth infection chain (Source – CrowdStrike)

The malware checks that WhatsApp Web is fully loaded and that the victim is already signed in before collecting contacts.

It excludes groups, broadcast lists, linked devices, unsaved contacts, the victim’s own number, and numbers outside Brazil. That selective approach suggests the operators want to limit noise while concentrating on their preferred targets.

Before sending messages, Astaroth retrieves a ZIP payload from a server selected in its configuration. It then chooses a Portuguese greeting based on the local time, attaches the ZIP file, and sends a body message to each selected contact.

The process makes malicious deliveries look more natural than generic spam and reflects the same danger seen in WhatsApp malware spreading tactics.

The spambot also uses WPPConnectWA-JS, a legitimate JavaScript library designed to interact with WhatsApp Web functions.

By abusing an otherwise legitimate tool, the operators can collect contacts and send messages through an active account rather than relying on a separately controlled fake profile.

The component operates in headless mode and removes browser indicators that normally reveal automation. That makes the campaign harder for victims to notice while it runs in the background.

Evolving Brazilian Banking Threat

Astaroth has been active since at least 2015 and is known for targeting Brazilian users through a layered infection chain.

A downloader, often delivered through a Windows shortcut file, retrieves further components that ultimately run the core banking trojan in memory.

Researchers found strong code and design overlap between the Astaroth spambot and Vareg, another WhatsApp-focused spambot that previously distributed Latin American banking trojans.

The shared functions, contact filtering, message delivery logic, and timing controls point to either a common developer or a code-sharing arrangement.

The apparent move from email spam to messaging platforms increases the credibility of each lure.

Brazilian banking trojan campaigns have repeatedly used local language, financial themes, and trusted communication channels, as seen in coverage of Brazilian banking trojan campaigns.

The Astaroth spambot’s internal component communication architecture (Source - CrowdStrike)
The Astaroth spambot’s internal component communication architecture (Source – CrowdStrike)

Users should treat unexpected ZIP files, links, and commands with caution, including those received from known contacts.

Organizations can reduce exposure by limiting WhatsApp Web where it is not needed, watching for unusual WebDriver downloads and hidden browser activity, and reviewing unexpected browser-profile copies.

Teams should also monitor downloads of the WPPConnectWA-JS library when it is not required for business activity.

Browser download protections, user awareness training, and prompt reporting of suspicious WhatsApp messages can help stop one compromised account from becoming a wider distribution point.

Indicators of compromise (IoCs):-

TypeIndicatorDescription
SHA-256c7c62303ee1a37fd7a6e2db9c590ba75c647bc4d22d7dca50Encrypted Astaroth spambot
SHA-256ec43a17685e3a555c2eb5f0a2802e9e45d5a2a5d49a080315Encrypted Astaroth spambot configuration
SHA-256d89105c4d567a95f674ed6eac538e32e288b658a4222a3d52e284a77782af4d5Decrypted Astaroth spambot
Domainstretar7[.]contabilfacil[.]sbsAstaroth installer component C2 server
Domaingraconxonjal[.]empresaeficiente[.]sbsAstaroth installer component C2 server
Domainplansonval[.]impostosrapido[.]topAstaroth installer component C2 server
SHA-2566168d63fad22a4e5e45547ca6116ef68bb5173e17e25fd171Vareg spambot Python version
SHA-256a1aa786e02fb9a37a71e0f76b052ab284ba877f2aaa2fb28fVareg spambot PowerShell version
URLhxxps://varegjopeaks[.]com/apiVareg Python-version C2 server
URLhxxps://docsmoonstudioclayworks[.]online/arquivVareg PowerShell-version C2 server

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Source: CybersecurityNews.com

Follow ShomoySoft for more: Follow on Facebook

💬 Comments (0)

Login to join the discussion.

No comments yet. Be the first!

Recommended for you