Astaroth

S0373

Malware.View on attack.mitre.org

About this malware

Astaroth is a Trojan and information stealer known to affect companies in Europe, Brazil, and throughout Latin America. It has been known publicly since at least late 2017.

Techniques used36

Procedure examples36

TechniqueProcedure example
T1016
System Network Configuration Discovery

Astaroth collects the external IP address from the system.

T1027.002
Software Packing

Astaroth uses a software packer called Pe123\RPolyCryptor.

T1027.010
Command Obfuscation

Astaroth has obfuscated and randomized parts of the JScript code it is initiating.

T1027.013
Encrypted/Encoded File

Astaroth has used an XOR-based algorithm to encrypt payloads twice with different keys.

T1041
Exfiltration Over C2 Channel

Astaroth exfiltrates collected information from its r1.log file to the external C2 server.

T1047
Windows Management Instrumentation

Astaroth uses WMIC to execute payloads.

T1055.012
Process Hollowing

Astaroth can create a new process in a suspended state from a targeted legitimate process in order to unmap its memory and replace it with malicious code.

T1056.001
Keylogging

Astaroth logs keystrokes from the victim's machine.

T1057
Process Discovery

Astaroth searches for different processes on the system.

T1059.003
Windows Command Shell

Astaroth spawns a CMD process to execute commands.

T1059.005
Visual Basic

Astaroth has used malicious VBS e-mail attachments for execution.

T1059.007
JavaScript

Astaroth uses JavaScript to perform its core functionalities.

T1074.001
Local Data Staging

Astaroth collects data in a plaintext file named r1.log before exfiltration.

T1082
System Information Discovery

Astaroth collects the machine name and keyboard language from the system.

T1102.001
Dead Drop Resolver

Astaroth can store C2 information on cloud hosting services such as AWS and CloudFlare and websites like YouTube and Facebook.

View all 36 procedure examples

Groups that use it0

None recorded.

Campaigns0

None recorded.

References3

  1. Cofense Astaroth Sept 2018 Open source
    Doaty, J., Garrett, P.. (2018, September 10). We’re Seeing a Resurgence of the Demonic Astaroth WMIC Trojan. Retrieved September 25, 2024.
  2. Cybereason Astaroth Feb 2019 Open source
    Salem, E. (2019, February 13). ASTAROTH MALWARE USES LEGITIMATE OS AND ANTIVIRUS PROCESSES TO STEAL PASSWORDS AND PERSONAL DATA. Retrieved April 17, 2019.
  3. Securelist Brazilian Banking Malware July 2020 Open source
    GReAT. (2020, July 14). The Tetrade: Brazilian banking malware goes global. Retrieved November 9, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.