Astaroth: Banking Trojan Abuses Github For Resilience
TL;DR: Mcafee labs describes an astaroth campaign that uses phishing to deploy autoit-based payloads, exfiltrates via ngrok, and pulls…
Astaroth: Banking Trojan Abuses Github For Resilience
TL;DR: Mcafee labs describes an astaroth campaign that uses phishing to deploy autoit-based payloads, exfiltrates via ngrok, and pulls steganographic configuration data from github images to survive c2 takedowns.
Context The campaign targets banking and cryptocurrency users, primarily across South America with a focus on Brazil, and includes some activity in Portugal and Italy. McAfee collaborated with GitHub to report and remove malicious repositories used by the actors.
What’s New Operators added a resilient fallback: instead of relying solely on private C2 servers, the malware fetches configuration updates embedded via steganography inside images hosted on GitHub. This approach makes takedown efforts less disruptive by moving config storage to a public platform.
Technical Breakdown The infection chain begins with a phishing email linking to a ZIP that contains a Windows shortcut (.lnk). The shortcut executes obfuscated JavaScript through mshta.exe, which downloads artifacts into ProgramData. Deployed files include an AutoIT compiled script and interpreter labeled Corsair.Yoga.06342.8476.366.log and Corsair.Yoga.06342.8476.366.exe, and an encrypted payload stack.tmp identified as the Astaroth component. The malware watches for access to banking and cryptocurrency sites, performs keylogging to harvest credentials, and uses Ngrok as a reverse proxy for exfiltration. When primary C2 endpoints are unreachable, the malware pulls updated configuration blobs from GitHub images that carry concealed configuration data via steganography.
Detection & Mitigation Detection should focus on anomalous execution of mshta.exe originating from shortcut files, unusual AutoIT interpreter execution and writes to ProgramData, and outbound connections associated with Ngrok services. Monitoring requests to GitHub image resources that return nonstandard payloads or show geo‑restricted behavior can also surface this campaign. McAfee reported the malicious repositories and GitHub removed the reported repos.
Limitations The summarized report provides filenames and behavioral indicators but does not enumerate a full set of IPs or file hashes in the public summary. Geo‑restricted delivery of stages means researchers may need regionally scoped telemetry to reproduce fetches.
Astaroth #GitHub #Ngrok #AutoIt

메타데이터
- post_id
- 46f6a0a7a4cc
- slug
- astaroth-banking-trojan-abuses-github-for-resilience-46f6a0a7a4cc
- url
- https://medium.com/@hasamba/astaroth-banking-trojan-abuses-github-for-resilience-46f6a0a7a4cc
- canonical_url
- https://medium.com/@hasamba/astaroth-banking-trojan-abuses-github-for-resilience-46f6a0a7a4cc
- author_url
- https://medium.com/@hasamba
- status
- ok
- fetched_at
- 2026-07-17 09:30:33