Astaroth infostealer just got better! It upgraded its obfuscation and anti-analysis tactics. These tactics ensure that the infostealer evades detection. According to researchers, this malware is “painful to analyze”.
Astaroth was discovered to be the main component of a spear-phishing campaign, targeting Brazilians, over the last nine months. The infostealer has been found to be modified and updated at an alarming rate. The malware evades detection by implementing a complicated labyrinth of anti-sandbox and anti-analysis checks.
The following IOCs have been found to be linked to the Astaroth campaign:
The Astaroth Trojan spam campaign is used to steal passwords and personal credentials from Brazilian users. Currently, it only actively exists in Brazil, and unleashing it on a global scale would wreak irreparable damage. Astaroth always stays ahead of its competitors by changing infrastructure at periodic intervals.
Read the original article and additional information at Cyware Social