Cybersecurity researchers are drawing attention to a new campaign distributing the Astaroth banking trojan, which uses GitHubto remain resilient to infrastructure takedowns.

“ Instead of relying solely on traditional command and control (C2) servers that can be taken down, these attackers leverage GitHub repositories to host malware configurations ,” McAfee Labs researchers Harshil Patel and Prabudh Chakravorty said .
“When law enforcement or security researchers take down the C2 infrastructure, Astaroth simply pulls new configurations from GitHub and continues to operate“.
See also: Hackers can inject malicious code into antivirus processes
The activity is mainly focused on Brazil, although the banking malware targets various countries in Latin America, including Mexico, Uruguay, Argentina, Paraguay, Chile, Bolivia, Peru, Ecuador, Colombia, Venezuela, and Panama.
This is not the first time that Astaroth campaigns have targeted Brazil. In July and October 2024, both Google and Trend Micro warned about threat groups called PINEAPPLE and Water Makara that used phishing emails to distribute the malware.
Astaroth: How do the latest attacks work?
The latest attack chain begins with a phishing email with the subject line DocuSign that contains a link that downloads a compressed Windows shortcut file (.lnk). When this file is opened, it installs Astaroth on the compromised computer.

The LNK file embeds obfuscated JavaScript, responsible for retrieving additional JavaScript from an external server. The new JavaScript code downloads various files from one of the randomly selected hard-coded servers.
See also: MalTerminal malware with LLM creates GPT-4 for Ransomware
This includes an AutoIt script executed by the JavaScript payload , which then loads and executes shellcode that loads a Delphi-based DLL to decrypt and inject the Astaroth malware into a newly created RegSvc.exe process.
Astaroth banking trojan
Astaroth is a Delphi malware designed to monitor victims' visits to banking or cryptocurrency websites and steal their credentials using keylogging. The collected information is transmitted to the attackers using the Ngrok reverse proxy.
It achieves this by checking the active browser window every second to see if a banking-related website is open. If these conditions are met, the malware records keystrokes. Some of the targeted websites include:
- caixa.gov[.]br
- safra.com[.]br
- itau.com[.]br
- bancooriginal.com[.]br
- santandernet.com[.]br
- btgpactual[.]com
- etherscan[.]io
- binance[.]com
- bitcointrade.com[.]br
- metamask[.]io
- foxbit.com[.]br
- localbitcoins[.]com
Astaroth also features analysis resistance and automatically terminates if it detects emulators, debuggers, and analysis tools such as QEMU Guest Agent, HookExplorer, IDA Pro, ImmunityDebugger, PE Tools, WinDbg, and Wireshark, among others.
Persistence achieved by dropping a LNK file into the Windows startup folder, which executes the AutoIT script to launch the malware automatically upon system reboot. The malware ensures that the system locale is not set to English or the US.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: RondoDox botnet: Targets dozens of devices via 56 n-day vulnerabilities

“Astaroth uses GitHub to update its configuration when C2 servers become inaccessible, hosting images on GitHub, which uses steganography to hide this information in plain sight,” McAfee noted.
In this way, the malware leverages a legitimate platform to host configuration files and create a resilient backup infrastructure when the main C2 servers go down. The company said it worked with the Microsoft subsidiary to remove the GitHub repositories, temporarily disabling the functionality.
