Astaroth infection chain | Image: Crowdstrike
At a glance
| Field | Detail |
|---|---|
| Actor | Unidentified LATAM threat actor behind the Astaroth/Guildma botnet |
| Activity | WhatsApp Web spambot spreading Astaroth banking trojan via victim contact lists |
| Targets | Brazil-based WhatsApp users; specifically filters for phone numbers with country code +55 |
| Scale | Victim count not confirmed; earlier related campaigns showed over 95% of impacted devices in Brazil |
| Law enforcement | No charges or arrests reported |
| Source | CrowdStrike, (authored by Kevin Ratto) |
TL;DR
The Astaroth WhatsApp spambot is a new weapon for a long-running LATAM banking trojan. Active since at least 2015, Astaroth’s operators added a WhatsApp spreading module in Q4 2025. The spambot runs a hidden browser in the background, grabs the victim’s contact list, and fires malware-laden messages to every saved contact in Brazil. No arrests have been reported.
What happened
In Q4 2025, the Astaroth installer’s command-and-control servers quietly began pushing a new component to infected machines: a WhatsApp Web spambot. This marked a sharp shift in tactics. Before this, Astaroth spread primarily through phishing emails. Now, according to CrowdStrike, the spambot “turn[s] victims into unwitting distributors of the malware by automatically messaging every contact in each victim’s WhatsApp contact list.”
The spambot runs its entire campaign without any visible window. It downloads a legitimate browser WebDriver, copies the victim’s Chrome or Edge profile to a hidden folder, and launches a headless browser, one that never appears on screen. Then it loads WhatsApp Web using the victim’s existing session, grabs all contacts with Brazilian phone numbers, and sends each one a time-appropriate greeting in Portuguese, a malware ZIP attachment, and a body message.
The Astaroth infection chain
Astaroth begins as a Windows shortcut file that runs a JScript downloader. That triggers an AutoIt-based loader, which decrypts and executes a Delphi loader DLL in memory. That DLL in turn decrypts and runs the Astaroth core payload. The new spambot module integrates into this same chain. CrowdStrike confirmed the spambot reuses the “same encryption, obfuscation, and encoding techniques employed in the core component,” pointing strongly to the same developer.
The spambot abuses a legitimate open-source JavaScript library called WPPConnect/WA-JS, a customer service automation tool to interact with the victim’s WhatsApp session. It also strips automation flags from the browser to avoid detection banners that would alert the user. The whole process runs silently behind the scenes.
Link to the Vareg spambot
Separately, CrowdStrike found extensive code overlaps between the Astaroth spambot and Vareg (also tracked as WATER SACI and Eternidade), an earlier WhatsApp-based LATAM spambot. Vareg distributed multiple banking trojans in October and November 2025 then went quiet. That timing coincides with Astaroth starting to distribute its own spambot component. Identical function names, contact-filtering logic, and identical delay values (50ms minimum, 200ms maximum between messages) appear in both tools. CrowdStrike also noted that Vareg’s developer likely used AI-assisted coding, based on code patterns.
Who is behind it
No individual or group has been charged in connection with Astaroth. The actor is described by CrowdStrike as an “established LATAM-focused threat actor” who has run this botnet for over a decade. CrowdStrike assesses with high confidence that the spambot was developed by the same person who built Astaroth’s core. With moderate confidence, it assesses the same actor also built Vareg. The claim that Vareg was absorbed into Astaroth activity is assessed with low confidence, based on limited campaign visibility.
Impact and scale
Astaroth exclusively targets Brazil. The spambot filters out non-Brazilian numbers and uses Portuguese-language templates timed to match the hour of day. Acronis had earlier documented a related campaign, codenamed Boto Cor-de-Rosa, in which a WhatsApp-based Astaroth variant spread via victim contact lists. That research found over 95% of impacted devices were in Brazil. Sophos also tracked a campaign (STAC3150) dating to September 2025 distributing Astaroth through WhatsApp attachments in Brazil. The CrowdStrike report represents the first deep technical analysis of the spambot component itself.
How to stay protected
The CrowdStrike technical deep dive includes a YARA detection rule and Falcon LogScale query alongside a full IoC list. Key defensive steps include watching for WebDriver downloads to unusual folders via PowerShell, hunting for folder names matching the ChromeAuto pattern in C:\Users\Public\Temp, and monitoring for headless browser activity. Blocking WhatsApp Web where it is not a business requirement removes a significant attack surface. Users should treat unexpected WhatsApp messages containing ZIP attachments with the same caution as unsolicited emails, even when the sender is a known contact.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.