


Perceptive Security
SOC/SIEM Consultancy

Guildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st)
Published:
1 September 2026 at 02:33:21
Alert date:
1 September 2026 at 03:00:40
Source:
isc.sans.edu
Ransomware & Malware, Email & Messaging
This article analyzes a Guildma (also known as Astaroth) malware infection originating from a Brazilian Portuguese phishing email. Guildma is a sophisticated banking trojan primarily targeting Brazilian users and organizations. The malware is typically distributed via spam email campaigns written in Brazilian Portuguese to target local victims. Astaroth/Guildma is known for its use of living-off-the-land binaries (LOLBins) to evade detection and execute its payload. The infection chain often involves malicious attachments or links leading to multi-stage loaders. This malware is capable of credential theft, keylogging, and intercepting banking transactions. The article was published on September 1st and appears on the SANS Internet Storm Center diary.
Technical details
Mitigation steps:
Affected products:
Windows
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
