Cybersecurity
Guildma Banking Trojan Resurfaces via Targeted Phishing Campaign
FORTSECURE GLOBAL· 2026-09-06🛰 SANS Internet Storm Center
#Banking#Incident Response#Vulnerability
A recent analysis highlights a targeted phishing campaign distributing the Guildma (Astaroth) banking malware via Portuguese-language lure emails. Organizations operating in relevant regions must reinforce endpoint controls and user awareness against credential theft.
Attack Anatomy and Infiltration Vector\n\nSecurity researchers have identified renewed activity involving Guildma, an established banking Trojan also recognized as Astaroth. The threat actors behind this operation leverage customized phishing emails written in Brazilian Portuguese, designed to appear as routine administrative or financial communications. Once an unsuspecting recipient interacts with the malicious email attachment or link, a multi-stage execution chain initiates. The attack bypasses standard perimeter defenses by downloading obfuscated payloads and deploying living-off-the-land techniques to establish persistence on the infected workstation.\n\nOnce embedded within the system, Guildma actively monitors target processes, focusing heavily on web browsers, financial portals, and enterprise login portals. The malware captures keystrokes, steals stored session tokens, and intercepts multi-factor authentication credentials in real time. Because Guildma targets corporate credentials alongside personal banking data, it poses an immediate risk of initial enterprise access for further lateral movement.\n\n## Recommended Defensive Strategies\n\nTo defend against Guildma and comparable identity-focused threats, enterprise defenders should implement robust perimeter and host-level protections:\n\n- Email Security Controls: Deploy advanced email filtering solutions capable of detecting dynamic payload delivery, suspicious localized phishing templates, and malicious scripts disguised as legitimate attachments.\n- Endpoint Detection and Response (EDR): Configure behavioral monitoring to flag suspicious process trees, unusual script executions via native binaries (such as PowerShell or WScript), and unexpected outbound connections from common desktop utilities.\n- User Awareness Programs: Train personnel to recognize localized social engineering tactics and mandate strict verification procedures prior to opening unexpected transactional documents.
แหล่งที่มา: SANS Internet Storm Center เผยแพร่ครั้งแรก: Tue, 01 Sep 2026 21:30:18 GMT บทความต้นฉบับ: อ่านต้นฉบับ
Source Attribution
แหล่งที่มา: SANS Internet Storm Center
เผยแพร่ครั้งแรก: Tue, 01 Sep 2026 21:30:18 GMT
บทความต้นฉบับ: https://isc.sans.edu/diary/rss/33300
ถูกใจบทความนี้
* Facebook / LinkedIn ไม่อนุญาตให้ใส่ข้อความให้ล่วงหน้า — กดปุ่มจะคัดลอกข้อความให้ก่อน เปิดหน้าแชร์แล้ววาง (paste) ได้เลย พรีวิวการ์ดจะแสดงอัตโนมัติเมื่อวางลิงก์
