ON September 1, 2026, Brad Duncan reported on a Guildma (Astaroth) malware infection that originated from a Brazilian Portuguese email. The infection was geofenced, delivering malware only to users with Brazilian IP addresses and language settings. The infected email contained a link leading to a zip file, which extracted a Windows shortcut that downloaded malicious payloads.
Key details include specific SHA-256 hashes for the files involved, indications of communication with malicious domains, and traffic analysis data using Wireshark. The report also provided screenshots of the process and indicators of the malware's activity.