isc.sans.edu 9/1/2026, 1:01:41 AM · external

Guildma Astaroth malware hits Brazil with geofenced phishing email

Guildma Astaroth malware hits Brazil with geofenced phishing email
CyberSIXT Evidence Panel Source marked as original reporting

ON September 1, 2026, Brad Duncan reported on a Guildma (Astaroth) malware infection that originated from a Brazilian Portuguese email. The infection was geofenced, delivering malware only to users with Brazilian IP addresses and language settings. The infected email contained a link leading to a zip file, which extracted a Windows shortcut that downloaded malicious payloads.

Key details include specific SHA-256 hashes for the files involved, indications of communication with malicious domains, and traffic analysis data using Wireshark. The report also provided screenshots of the process and indicators of the malware's activity.

View full article

Article by CyberSIXT