CuraSec

Learn active

Guildma (Astaroth) Banking Trojan Delivered via Brazilian Portuguese Email

2026-09-01 15:28 UTC · SANS ISC · read the source ↗ #astaroth#banking-trojan#phishing
  • Engineer — Skip
  • SOC/IR — Learn: SANS ISC diary on the Astaroth/Guildma infection chain; useful for understanding email-lure TTPs, but the summary is too thin to extract IOCs — read the full diary if this actor targets your sector.
  • Leader — Skip
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.