NEW: Unlock the Future of Finance with CRYPTO ENDEVR - Explore, Invest, and Prosper in Crypto!
Crypto Endevr
  • Top Stories
    • Latest News
    • Trending
    • Editor’s Picks
  • Media
    • YouTube Videos
      • Interviews
      • Tutorials
      • Market Analysis
    • Podcasts
      • Latest Episodes
      • Featured Podcasts
      • Guest Speakers
  • Insights
    • Tokens Talk
      • Community Discussions
      • Guest Posts
      • Opinion Pieces
    • Artificial Intelligence
      • AI in Blockchain
      • AI Security
      • AI Trading Bots
  • Learn
    • Projects
      • Ethereum
      • Solana
      • SUI
      • Memecoins
    • Educational
      • Beginner Guides
      • Advanced Strategies
      • Glossary Terms
No Result
View All Result
Crypto Endevr
  • Top Stories
    • Latest News
    • Trending
    • Editor’s Picks
  • Media
    • YouTube Videos
      • Interviews
      • Tutorials
      • Market Analysis
    • Podcasts
      • Latest Episodes
      • Featured Podcasts
      • Guest Speakers
  • Insights
    • Tokens Talk
      • Community Discussions
      • Guest Posts
      • Opinion Pieces
    • Artificial Intelligence
      • AI in Blockchain
      • AI Security
      • AI Trading Bots
  • Learn
    • Projects
      • Ethereum
      • Solana
      • SUI
      • Memecoins
    • Educational
      • Beginner Guides
      • Advanced Strategies
      • Glossary Terms
No Result
View All Result
Crypto Endevr
No Result
View All Result

Astaroth Banking Trojan Harnessing GitHub to Steal Crypto Credentials

Astaroth Banking Trojan Harnessing GitHub to Steal Crypto Credentials
Share on FacebookShare on Twitter

rewrite this content

In brief

  • McAfee has uncovered a Trojan campaign that uses GitHub to redirect malware to new servers whenever existing servers are taken down.
  • The malware is primarily targeting countries in South America, with a particular focus on Brazil.
  • The virus is uploaded via phishing emails, and is capable of stealing banking and crypto credentials.

Hackers are deploying a banking Trojan that makes use of GitHub repositories whenever its servers are taken down, according to research from cybersecurity firm McAfee.

Dubbed Astaroth, the Trojan virus is spread via phishing emails that invite victims to download a Windows (.lnk) file, which installs the malware on a host computer.

Astaroth runs in the background of a victim’s device, using keylogging to steal banking and crypto credentials, and sending such credentials using the Ngrok reverse proxy (an intermediary between servers).

Its unique feature is that Astaroth uses GitHub repositories to update its server configuration whenever its command-and-control server is taken down, which usually happens because of intervention from cybersecurity firms or law enforcement agencies.

“GitHub is not used to host the malware itself, but just to host a configuration that points to the bot server,” said Abhishek Karnik, Director for Threat Research and Response at McAfee.

Speaking to Decrypt, Karnik explained that the malware’s deployers are using GitHub as a resource to direct victims to updated servers, which distinguishes the exploit from previous instances in which GitHub has been harnessed.

This includes an attack vector discovered by McAfee in 2024, in which bad actors inserted the Redline Stealer malware into GitHub repositories, something which has been repeated this year in the GitVenom campaign.

“However, in this case, it’s not malware that is being hosted but a configuration that manages how the malware communicates with its backend infrastructure,” Karnik added.

As with the GitVenom campaign, Astaroth’s ultimate purpose is to exfiltrate credentials that can be used to steal a victim’s crypto or to make transfers out of their bank accounts.

“We don’t have data about how much money or crypto it has stolen, but it appears to be very prevalent, especially in Brazil,” said Karnik.

Targeting South America

It seems that Astaroth has primarily targeted South American territories, including Mexico, Uruguay, Argentina, Paraguay, Chile, Bolivia, Peru, Ecuador, Colombia, Venezuela and Panama.

While it is also capable of targeting Portugal and Italy, the malware is written so that it is not uploaded to systems in the United States or other English-speaking countries (such as England).

The malware shuts down its host system if it detects that analysis software is being operated, while it’s designed to run keylogging functions if it detects that a web browser is visiting certain banking sites.

These include caixa.gov.br, safra.com.br, itau.com.br, bancooriginal.com.br, santandernet.com.br and btgpactual.com.

It has also been written to target the following crypto-related domains: etherscan.io, binance.com, bitcointrade.com.br, metamask.io, foxbit.com.br and localbitcoins.com.

In the face of such threats, McAfee advises that users do not open attachments or links from unknown senders, while also using up-to-date antivirus software and two-factor authentication.

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.

in well organized HTML format with all tags properly closed. Create appropriate headings and subheadings to organize the content. Ensure the rewritten content is approximately 1500 words. Do not include the title and images. please do not add any introductory text in start and any Note in the end explaining about what you have done or how you done it .i am directly publishing the output as article so please only give me rewritten content. At the end of the content, include a “Conclusion” section and a well-formatted “FAQs” section.

cryptoendevr

cryptoendevr

Related Stories

Maryland Man Sentenced for Helping North Korea Infiltrate US Tech Firms

Maryland Man Sentenced for Helping North Korea Infiltrate US Tech Firms

December 7, 2025
0

rewrite this content In brief Maryland man Minh Phuong Ngoc Vong has been sentenced to 15 months in jail for...

Trump DOJ Wants Terra Founder Do Kwon Behind Bars for 12 Years, Citing SBF Sentence

Trump DOJ Wants Terra Founder Do Kwon Behind Bars for 12 Years, Citing SBF Sentence

December 6, 2025
0

rewrite this content In brief The DOJ wants Do Kwon to receive the full 12-year prison sentence allowed under the...

Crypto Holiday Gift Guide 2025

Crypto Holiday Gift Guide 2025

December 6, 2025
0

rewrite this content With the holiday season just around the corner, it’s time to start piling presents under the tree....

Professor Coin: When Bitcoin Sneezes—How Crypto and Equities Caught the Same Cold

Professor Coin: When Bitcoin Sneezes—How Crypto and Equities Caught the Same Cold

December 6, 2025
0

rewrite this content In brief Academic literature increasingly finds that crypto and equities are tightly intertwined, especially during periods of...

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended

Spot Bitcoin ETFs see 8M outflow: Are investors abandoning BTC?

Spot Bitcoin ETFs see $358M outflow: Are investors abandoning BTC?

December 16, 2025
Bitcoin (BTC) Retreats to K, Hyperliquid (HYPE) Plunges by 9% Daily: Market Watch

Bitcoin (BTC) Retreats to $90K, Hyperliquid (HYPE) Plunges by 9% Daily: Market Watch

December 16, 2025
Ethereum 2-Year Trend Maps Out This Unique Crash Path To Bottom At ,187

Ethereum 2-Year Trend Maps Out This Unique Crash Path To Bottom At $2,187

December 16, 2025
Binance Executive Yi He’s WeChat Hacked in K Meme Coin Scam

Binance Executive Yi He’s WeChat Hacked in $55K Meme Coin Scam

December 16, 2025
Why BitMine Is Accumulating Ether as ETFs See Outflows

Why BitMine Is Accumulating Ether as ETFs See Outflows

December 16, 2025

Our Newsletter

Join TOKENS for a quick weekly digest of the best in crypto news, projects, posts, and videos for crypto knowledge and wisdom.

CRYPTO ENDEVR

About Us

Crypto Endevr aims to simplify the vast world of cryptocurrencies and blockchain technology for our readers by curating the most relevant and insightful articles from around the web. Whether you’re a seasoned investor or new to the crypto scene, our mission is to deliver a streamlined feed of news and analysis that keeps you informed and ahead of the curve.

Links

Home
Privacy Policy
Terms and Services

Resources

Glossary

Other

About Us
Contact Us

Our Newsletter

Join TOKENS for a quick weekly digest of the best in crypto news, projects, posts, and videos for crypto knowledge and wisdom.

© Copyright 2024. All Right Reserved By Crypto Endevr.

No Result
View All Result
  • Top Stories
    • Latest News
    • Trending
    • Editor’s Picks
  • Media
    • YouTube Videos
      • Interviews
      • Tutorials
      • Market Analysis
    • Podcasts
      • Latest Episodes
      • Featured Podcasts
      • Guest Speakers
  • Insights
    • Tokens Talk
      • Community Discussions
      • Guest Posts
      • Opinion Pieces
    • Artificial Intelligence
      • AI in Blockchain
      • AI Security
      • AI Trading Bots
  • Learn
    • Projects
      • Ethereum
      • Solana
      • SUI
      • Memecoins
    • Educational
      • Beginner Guides
      • Advanced Strategies
      • Glossary Terms

Copyright © 2024. All Right Reserved By Crypto Endevr