Attackers who are distributing Guildma malware have shifted their focus on entities outside Brazil. The banking trojan, better known as Astaroth, is reportedly targeting 130 banks along with popular web services such as Netflix, Amazon, Facebook, and Gmail. The discovery was made by security firm Avast.
Guildma is said to have originated in Brazil and is known for primarily targeting Brazilian companies.
Key highlights
Worth noting
In an analysis report, Avast researchers capture the developments of Guildma, which was created in 2015. They indicate that the creators of the malware have brought forth numerous implementation for sophistication.
“The malware authors have used large amounts of domains, various infection and stealing techniques, and programming languages (Delphi, JS, VBS,..) during Guildma's long existence,” wrote the researchers. However, the actors used similar code most of the times which helped the researchers spot the malware campaign.
Publisher