Astaroth Malware Exploits WhatsApp to Spread Itself

The Astaroth banking trojan has evolved to exploit WhatsApp Web sessions, transforming compromised accounts into vectors for further malware distribution. This development underscores the increasing sophistication of cyber threats targeting popular communication platforms.

Traditionally, Astaroth propagated through phishing emails and malicious shortcut files that initiated hidden infection chains on Windows systems. The latest iteration introduces a spambot component that leverages an infected user’s active WhatsApp Web session to disseminate the malware to their contacts. By sending convincing messages accompanied by malicious ZIP attachments, the malware capitalizes on the trust inherent in familiar senders, thereby enhancing the likelihood of successful infections.

Security researchers identified this new spambot component in late 2025, noting its significant expansion of Astaroth’s operational capabilities. The campaign predominantly targets Brazilian users, as evidenced by the use of Portuguese-language messages, filtering for Brazilian phone numbers, and browser settings aligned with local preferences.

Mechanism of the WhatsApp-Based Propagation

Upon infection, the spambot initiates a concealed browser session using WebDriver, a legitimate browser automation tool. It replicates the victim’s browser profile, including session cookies and saved data, to access WhatsApp Web without displaying a visible browser window. The malware ensures that WhatsApp Web is fully loaded and that the victim is authenticated before proceeding to collect contacts.

To maintain a low profile, the spambot excludes groups, broadcast lists, linked devices, unsaved contacts, the victim’s own number, and non-Brazilian numbers. This selective approach indicates a strategic focus on specific targets while minimizing detection risks.

Before dispatching messages, Astaroth retrieves a malicious ZIP payload from a predefined server. It then selects an appropriate Portuguese greeting based on the local time, attaches the ZIP file, and sends a personalized message to each chosen contact. This method enhances the authenticity of the communication, increasing the chances that recipients will open the attachment.

The spambot employs WPPConnectWA-JS, a legitimate JavaScript library designed for interacting with WhatsApp Web functions. By exploiting this tool, the malware can collect contacts and send messages through an active account, avoiding the need for separately controlled fake profiles. Operating in headless mode and removing browser indicators that typically reveal automation, the campaign remains stealthy and difficult for victims to detect.

Implications and Broader Context

Astaroth has been active since at least 2015, primarily targeting Brazilian users through complex infection chains. The introduction of this WhatsApp-based propagation method signifies a notable shift from email spam to messaging platforms, leveraging the credibility of trusted communication channels to enhance the effectiveness of malware distribution.

Researchers have observed strong code and design similarities between the Astaroth spambot and Vareg, another WhatsApp-focused spambot previously used to distribute Latin American banking trojans. Shared functions, contact filtering mechanisms, message delivery logic, and timing controls suggest either a common developer or a code-sharing arrangement.

This evolution highlights the adaptability of cybercriminals in exploiting widely used communication platforms to propagate malware. Users are advised to exercise caution when receiving unsolicited messages, even from known contacts, and to avoid opening attachments or clicking on links without verifying their authenticity. Implementing robust security measures, such as regular software updates and the use of reputable antivirus solutions, remains crucial in mitigating the risks associated with such sophisticated threats.