← Blog · · df00tech

Guildma (Astaroth) Malware Spreading via Brazilian Portuguese Phishing Emails

security-news campaign

What Happened

The SANS Internet Storm Center reported on September 1, 2026, on a malware infection chain delivered via phishing emails written in Brazilian Portuguese, leading to a Guildma (also known as Astaroth) infection. Guildma/Astaroth is a long-running banking trojan family that has historically targeted users in Brazil and other Latin American countries.

The ISC diary is titled "Guildma (Astaroth) malware infection from Brazilian Portuguese email" and is categorized as an active campaign observation; full technical details are available in the original source.

Why It Matters for Defenders

Guildma/Astaroth campaigns have a track record of evolving delivery chains, often abusing legitimate system binaries (LOLBins) for staged execution and using regionally-targeted lures to improve click-through rates. Organizations with Brazilian or Latin American user bases, or with employees who read Portuguese-language correspondence, are the most directly exposed. Banking trojans in this family are typically financially motivated, targeting credentials for financial and business applications.

What Defenders Should Watch For

  • Inbound email with Brazilian Portuguese-language content, especially from unfamiliar senders, containing attachments or links leading to archive files or script-based droppers.
  • Unusual child-process chains spawned from email clients or browsers, particularly involving scripting engines (e.g., JavaScript, VBScript, PowerShell) or living-off-the-land binaries.
  • Outbound connections to newly registered or low-reputation domains shortly after a user opens an email attachment.
  • User-awareness reinforcement for staff who receive Portuguese-language correspondence, particularly around unsolicited attachments and shortened or redirect links.

Because the ISC diary does not detail specific indicators or a full execution chain in the summary available here, defenders should consult the source directly for IOCs and technical specifics before building targeted detections.

Developing Intel

This is a preliminary write-up based on a same-day SANS ISC diary entry; the full technical breakdown, indicators of compromise, and infection chain details should be reviewed directly at the source. See the original diary at isc.sans.edu/diary/rss/33300.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.