← Back to list

Astaroth: Banking Trojan Abuses Github For Resilience

TL;DR: Mcafee labs describes an astaroth campaign that uses phishing to deploy autoit-based payloads, exfiltrates via ngrok, and pulls…

Yaniv · 2025-10-13 10:08 · 0 claps · 1.5 min read
#astaroth #github #ngrok #autoit
Open on Medium ↗
Wiki topics: LLM · Large Language Models ECO · Economy · General MKT · Marketing · General 🔒 · Cybersecurity 🔓 · Open Source 🚀 · Self Improvement 🔮 · Astrology & Mysticism

Astaroth: Banking Trojan Abuses Github For Resilience

TL;DR: Mcafee labs describes an astaroth campaign that uses phishing to deploy autoit-based payloads, exfiltrates via ngrok, and pulls steganographic configuration data from github images to survive c2 takedowns.

Context The campaign targets banking and cryptocurrency users, primarily across South America with a focus on Brazil, and includes some activity in Portugal and Italy. McAfee collaborated with GitHub to report and remove malicious repositories used by the actors.

What’s New Operators added a resilient fallback: instead of relying solely on private C2 servers, the malware fetches configuration updates embedded via steganography inside images hosted on GitHub. This approach makes takedown efforts less disruptive by moving config storage to a public platform.

Technical Breakdown The infection chain begins with a phishing email linking to a ZIP that contains a Windows shortcut (.lnk). The shortcut executes obfuscated JavaScript through mshta.exe, which downloads artifacts into ProgramData. Deployed files include an AutoIT compiled script and interpreter labeled Corsair.Yoga.06342.8476.366.log and Corsair.Yoga.06342.8476.366.exe, and an encrypted payload stack.tmp identified as the Astaroth component. The malware watches for access to banking and cryptocurrency sites, performs keylogging to harvest credentials, and uses Ngrok as a reverse proxy for exfiltration. When primary C2 endpoints are unreachable, the malware pulls updated configuration blobs from GitHub images that carry concealed configuration data via steganography.

Detection & Mitigation Detection should focus on anomalous execution of mshta.exe originating from shortcut files, unusual AutoIT interpreter execution and writes to ProgramData, and outbound connections associated with Ngrok services. Monitoring requests to GitHub image resources that return nonstandard payloads or show geo‑restricted behavior can also surface this campaign. McAfee reported the malicious repositories and GitHub removed the reported repos.

Limitations The summarized report provides filenames and behavioral indicators but does not enumerate a full set of IPs or file hashes in the public summary. Geo‑restricted delivery of stages means researchers may need regionally scoped telemetry to reproduce fetches.

Astaroth #GitHub #Ngrok #AutoIt

SOURCE: https://www.mcafee.com/blogs/other-blogs/mcafee-labs/astaroth-banking-trojan-abusing-github-for-resilience/


메타데이터
post_id
46f6a0a7a4cc
slug
astaroth-banking-trojan-abuses-github-for-resilience-46f6a0a7a4cc
url
https://medium.com/@hasamba/astaroth-banking-trojan-abuses-github-for-resilience-46f6a0a7a4cc
canonical_url
https://medium.com/@hasamba/astaroth-banking-trojan-abuses-github-for-resilience-46f6a0a7a4cc
author_url
https://medium.com/@hasamba
status
ok
fetched_at
2026-07-17 09:30:33