Astaroth Banking Malware Exploits GitHub for Hosting Configuration Files
McAfee's Threat Research team has identified a new campaign involving the Astaroth malware, showcasing a significant shift in malware infrastructure tactics.
McAfee's Threat Research team has identified a new campaign involving the Astaroth malware, showcasing a significant shift in malware infrastructure tactics.
This latest variant of Astaroth has moved away from traditional command-and-control (C2) server dependencies, opting instead to use GitHub repositories to host essential malware configurations. The malware exploits GitHub's legitimate infrastructure to maintain persistent operations, particularly when traditional C2 servers are disrupted.
The malware uses steganography to hide configuration data within image files hosted on GitHub. Configurations are updated every two hours by fetching disguised files from GitHub. This technique enhances malware resilience, making it harder to eliminate compared to traditional C2 servers.
McAfee researchers have identified multiple GitHub repositories containing these malicious files and have collaborated with GitHub's security team to remove them. However, the ease of creating new repositories suggests an ongoing challenge in combating this threat.
The Astaroth campaign begins with phishing emails themed around DocuSign notifications and resume documents. These emails contain links that download compressed Windows shortcut files (.lnk), which execute obfuscated JavaScript commands through mshta.exe.
The malware exploits GitHub's legitimate infrastructure to maintain persistent operations, particularly when traditional C2 servers are disrupted.
The malware targets mainly South American countries, with a focus on banking institutions and cryptocurrency platforms in Brazil. It also extends its operations to Portugal and Italy.
Astaroth implements sophisticated anti-analysis measures, detecting security research tools and ensuring system locale settings do not correspond to United States or English configurations. It maintains persistence through LNK files in system startup folders, ensuring execution upon system restart.
Communication with C2 infrastructure uses custom binary protocols for data transmission, while GitHub-based configuration updates are retrieved through disguised image files.
To protect against Astaroth and similar threats, organizations and individuals should:
Enhance email security awareness to avoid suspicious attachments and links. Implement two-factor authentication on financial platforms. Maintain updated antivirus solutions with real-time scanning capabilities. Regularly apply system updates and security patches.
The exploitation of GitHub by the Astaroth campaign represents a concerning development in malware tactics, highlighting the challenges in combatting adaptive malware that leverages trusted platforms for persistence.
Based on reporting by GBHackers.
