Netskope Threat Labs

Astaroth

ATP Sandbox Adv. HeuristicsNetskope IPS

Astaroth is a trojan and information stealer known to affect companies in Europe, Brazil, and throughout Latin America, publicly known since at least late 2017.

First seen
May 2022
Last seen
October 2026
Guildma

36 techniques across 9 tactics.

TA0001 Initial Access

TA0002 Execution

TA0003 Persistence

TA0005 Stealth

TA0006 Credential Access

  • T1552Unsecured Credentials
  • T1555Credentials from Password Stores

TA0007 Discovery

  • T1016System Network Configuration Discovery
  • T1057Process Discovery
  • T1082System Information Discovery
  • T1124System Time Discovery
  • T1518Software Discovery

TA0009 Collection

TA0011 Command and Control

TA0010 Exfiltration

  • T1041Exfiltration Over C2 Channel
Alert Name
ByteCode-MSIL.Trojan.Guildma
Document-HTML.Downloader.Astaroth
Email-MSG.Downloader.Astaroth
Script-JS.Downloader.Astaroth
Script-JS.Downloader.Guildma
Script-JS.Trojan.Astaroth
Script-JS.Trojan.Guildma
Shortcut.Trojan.Astaroth
Win32.Spyware.Guildma
Win32.Trojan.Astaroth