AntiMalwareJuly 31, 2026🇷🇺Translated from Russian

Astaroth Trojan Hijacks WhatsApp Web Sessions to Spread Banking Malware to Contacts

The operators of the banking Trojan Astaroth, also known as Guildma, have equipped infected Windows machines with the ability to autonomously distribute malicious archives through WhatsApp Web. Victims now face not only the risk of banking data theft but also the possibility of unknowingly forwarding the Trojan to their own contacts, according to researchers at CrowdStrike.

Previously, Astaroth spread mainly through phishing emails. In late 2025 the operators added a dedicated spam module for WhatsApp Web. The module copies the profile of Chrome or Edge, downloads the official WebDriver, and launches the browser in headless mode. It then attaches to an already authenticated WhatsApp Web session using the legitimate WPPConnect/WA-JS library.

From the user’s perspective the process remains silent. In the background the bot iterates through the address book and sends three messages to every contact: a time-appropriate greeting, a ZIP archive containing the Astaroth loader, and a closing text. Links and wording are randomized to avoid pattern-based detection.

Because the messages arrive from a known person and begin with natural phrases such as “good morning,” recipients are far more likely to open the attachment. The spam-bot code shares structural and functional traits with tools used by other Latin American groups, including Vareg, indicating either a common developer or active sharing of components within the regional cybercrime ecosystem.

Observable signs of infection include PowerShell downloads of WebDriver, the appearance of ChromeAuto_ folders under C:\Users\Public\Temp, headless Chromium processes, and network connections to WPPConnect components. Astaroth has effectively turned WhatsApp Web into a delivery service for its banking payload, with the victim unknowingly covering the distribution costs.

Related articles

AntiMalwareMalware & Botnets

Microsoft Removes WMIC from Windows 11 After Years of Abuse as LOLBIN by Ransomware and Attackers

Microsoft has begun permanently removing the legacy WMIC command-line utility from Windows 11, starting with versions 24H2 and 25H2. The tool is no longer available in fresh installations, has been dropped as an optional component, and is absent from the latest beta builds. WMIC provided text-based access to Windows Management Instrumentation for querying hardware, processes, services, and security software, as well as performing administrative tasks. Although the underlying WMI technology remains untouched, Microsoft has deprecated the command shell due to its long-standing use as a LOLBIN in cyberattacks. Ransomware operators have leveraged WMIC to delete shadow copies and hinder recovery, while other attackers used it to enumerate and disable security tools or add exclusions in Microsoft Defender. Administrators are directed to migrate to PowerShell, COM API, .NET libraries, and modern scripting languages, which will require rewriting legacy automation scripts.

AntiMalwareMalware & Botnets

Octagon Malware-as-a-Service Platform Targets Android Banking Apps and Crypto Wallets for $1400 Monthly Subscription

Researchers at iVerify have uncovered the previously unknown Octagon platform, a malware-as-a-service offering sold by a Russian-speaking actor under the handle AndroidKitKat. The service first appeared on underground forums on June 1, 2026, with version 1.2 released by June 29, providing a ready-made control panel for account takeovers across banks, crypto exchanges, messengers, and wallets. Infection starts with a disguised APK that requests Accessibility Services permissions, after which the trojan can read UI elements, simulate taps, launch apps, and overlay phishing screens on services such as Trust Wallet, Binance, and MEXC. The malware also intercepts SMS one-time codes, spoofs the system lock screen to steal PINs or patterns, and supports VNC-style remote control while operating on the victim’s own device to evade anti-fraud systems. Three related builds—Octagon, Lifted Dreams, and BahrDate—were identified, with one variant displaying a visual novel to distract users while the spyware runs in the background. The campaign underscores the growing threat of sophisticated Android remote-access trojans sold on a subscription basis.

AntiMalwareMalware & Botnets

BTMOB Platform Turns Android Banking Trojan into Customizable Fraud Campaign Constructor

Researchers at QuimeraX have uncovered BTMOB, a platform that evolved from a banking trojan into a full-featured builder for fraudulent Android campaigns. The service allows clients without development skills to select an app name, icon, command-and-control server, permissions, and social-engineering lure, after which the system automatically compiles a ready-to-use APK. The package includes an Android payload, dropper, VB.NET control panel, PHP and MySQL backend, and build tools that enable rapid production of localized copies of streaming services, banking protection modules, parcel trackers, and social networks. One BTMOB 2.5 variant was distributed via a phishing site mimicking the Turkish iNat TV service, while Brazilian operators created fake Google Play pages impersonating Nubank, TikTok, and the government portal Gov.BR. After installation, the trojan requests accessibility permissions and, once granted, grants operators near-complete device control including screen viewing, keystroke capture, audio recording, and real-time WebSocket interaction that lets attackers perform actions directly on the victim’s device. Analysts link BTMOB to the SpySolr family and earlier commercial RATs CypherRAT and CraxsRAT, which had already attracted more than 100 licensees.

BoletimSecMalware & Botnets

Dysphoria Botnet Compromises Nearly 300,000 Devices for DDoS Attacks and Residential Proxy Services

The Dysphoria botnet has infected approximately 296,000 devices, including routers, IP cameras, gateways, and embedded Linux systems. Researchers first observed the threat in the first quarter of 2026, noting rapid evolution from the jackskid and fbot families. The infrastructure is primarily used for DDoS attacks but has expanded to offer residential proxy capabilities. Infection occurs through brute-force attacks on Telnet and SSH services with weak credentials, as well as known remote code execution vulnerabilities in IoT equipment. A key technical advancement involves the use of Ethereum and Solana blockchain domains for command-and-control infrastructure, making takedowns significantly harder. Compromised devices can also function as relays by leveraging UPnP to expose ports and hide criminal traffic origins. Operators advertise attack capacity of up to 4 Tbps and sell DDoS services in structured commercial packages targeting internet services and gaming platforms worldwide.