Close Menu
CoinslopesCoinslopes
    Facebook X (Twitter) Instagram
    CoinslopesCoinslopes
    Trending
    • We Asked 3 AIs if Binance Coin (BNB) Can Flip Ethereum (ETH) This Cycle
    • XLM Rises 6% to Recover From Weekend Plunge
    • Support At $105K Holds, But Bears Dominate
    • Dogecoin To Take Another Shot At The Moon As Classic Pattern Reappears
    • Want Better Results From an AI Chatbot? Be a Jerk
    • SPX, DXY, BTC, ETH, BNB, XRP, SOL, DOGE, ADA, HYPE Price Predictions
    • Nobel Peace Prize Bets on Polymarket Under Scrutiny: Report
    • Phemex Announces Halloween Futures Trading Festival With 200,000 USDT Prize Pool
    • Home
    • Bitcoin
    • Exchanges
    • Press Release
    • Crypto Startups
    • DeFi Ecosystem
    • Token Insights
    • Ethereum
    • NFT & Metaverse
    CoinslopesCoinslopes
    Home»Ethereum»Astaroth Banking Trojan Harnessing GitHub to Steal Crypto Credentials
    Ethereum

    Astaroth Banking Trojan Harnessing GitHub to Steal Crypto Credentials

    adminBy adminOctober 11, 2025No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Decrypt logo
    Share
    Facebook Twitter LinkedIn Pinterest Email

    In brief

    • McAfee has uncovered a Trojan campaign that uses GitHub to redirect malware to new servers whenever existing servers are taken down.
    • The malware is primarily targeting countries in South America, with a particular focus on Brazil.
    • The virus is uploaded via phishing emails, and is capable of stealing banking and crypto credentials.

    Hackers are deploying a banking Trojan that makes use of GitHub repositories whenever its servers are taken down, according to research from cybersecurity firm McAfee.

    Dubbed Astaroth, the Trojan virus is spread via phishing emails that invite victims to download a Windows (.lnk) file, which installs the malware on a host computer.

    Astaroth runs in the background of a victim’s device, using keylogging to steal banking and crypto credentials, and sending such credentials using the Ngrok reverse proxy (an intermediary between servers).

    Its unique feature is that Astaroth uses GitHub repositories to update its server configuration whenever its command-and-control server is taken down, which usually happens because of intervention from cybersecurity firms or law enforcement agencies.

    “GitHub is not used to host the malware itself, but just to host a configuration that points to the bot server,” said Abhishek Karnik, Director for Threat Research and Response at McAfee.

    Speaking to Decrypt, Karnik explained that the malware’s deployers are using GitHub as a resource to direct victims to updated servers, which distinguishes the exploit from previous instances in which GitHub has been harnessed.

    This includes an attack vector discovered by McAfee in 2024, in which bad actors inserted the Redline Stealer malware into GitHub repositories, something which has been repeated this year in the GitVenom campaign.

    “However, in this case, it’s not malware that is being hosted but a configuration that manages how the malware communicates with its backend infrastructure,” Karnik added.

    As with the GitVenom campaign, Astaroth’s ultimate purpose is to exfiltrate credentials that can be used to steal a victim’s crypto or to make transfers out of their bank accounts.

    “We don’t have data about how much money or crypto it has stolen, but it appears to be very prevalent, especially in Brazil,” said Karnik.

    Targeting South America

    It seems that Astaroth has primarily targeted South American territories, including Mexico, Uruguay, Argentina, Paraguay, Chile, Bolivia, Peru, Ecuador, Colombia, Venezuela and Panama.

    While it is also capable of targeting Portugal and Italy, the malware is written so that it is not uploaded to systems in the United States or other English-speaking countries (such as England).

    The malware shuts down its host system if it detects that analysis software is being operated, while it’s designed to run keylogging functions if it detects that a web browser is visiting certain banking sites.

    These include caixa.gov.br, safra.com.br, itau.com.br, bancooriginal.com.br, santandernet.com.br and btgpactual.com.

    It has also been written to target the following crypto-related domains: etherscan.io, binance.com, bitcointrade.com.br, metamask.io, foxbit.com.br and localbitcoins.com.

    In the face of such threats, McAfee advises that users do not open attachments or links from unknown senders, while also using up-to-date antivirus software and two-factor authentication.

    Daily Debrief Newsletter

    Start every day with the top news stories right now, plus original features, a podcast, videos and more.

    Astaroth Banking Credentials Crypto GitHub Harnessing Steal Trojan
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleZORA Doubles After Listing Robinhood and OKX
    Next Article Why Are Crypto Markets Falling in ‘Uptober’? Analysts Weigh In
    admin
    • Website

    Related Posts

    Dogecoin To Take Another Shot At The Moon As Classic Pattern Reappears

    October 13, 2025

    Jiuzi Holdings, Inc. (JZXN) Secures 100 Bitcoin Via Private Placement, Signaling New Phase In Crypto Treasury Deployment

    October 13, 2025

    BitMine Immersion (BMNR) Announces ETH Holdings Exceeding 3.03 Million Tokens And Total Crypto And Cash Holdings Of $12.9 Billion

    October 13, 2025
    Leave A Reply Cancel Reply

    • Facebook
    • Twitter
    • Instagram
    • Pinterest
    Our Picks

    We Asked 3 AIs if Binance Coin (BNB) Can Flip Ethereum (ETH) This Cycle

    October 13, 2025

    XLM Rises 6% to Recover From Weekend Plunge

    October 13, 2025

    Support At $105K Holds, But Bears Dominate

    October 13, 2025

    Dogecoin To Take Another Shot At The Moon As Classic Pattern Reappears

    October 13, 2025

    Want Better Results From an AI Chatbot? Be a Jerk

    October 13, 2025
    Teach

    Jiuzi Holdings, Inc. Announces Phased Rollout Of $1 Billion Cryptocurrency Acquisition Plan; First Bitcoin Purchase To Be Completed Within Two Weeks

    October 8, 2025

    Bitcoin Price Surges Past $124,000 After Minor Pullback

    October 8, 2025

    Coinbase Enables Staking for NY Residents after Regulatory Approval

    October 8, 2025

    3 reasons why XRP’s time spent under $3 could be short-lived

    October 8, 2025
    About

    Welcome to Coinslopes, your trusted digital platform for exploring the dynamic world of cryptocurrency and blockchain technology.
    At Coinslopes, we aim to bridge innovation with information, empowering crypto enthusiasts, traders, and investors to make informed decisions in the fast-paced blockchain ecosystem.

    Facebook X (Twitter) Pinterest LinkedIn VKontakte
    Popular Posts

    Support At $105K Holds, But Bears Dominate

    October 13, 2025

    Coinbase’s 1,000 Bitcoin Transfer Raises Major Suspicion

    October 12, 2025

    When You Tell AI Models to Act Like Women, Most Become More Risk-Averse: Study

    October 11, 2025
    Letest

    Nobel Peace Prize Bets on Polymarket Under Scrutiny: Report

    October 13, 2025

    Solana holds near $220 amid 50% drop in daily transactions, ETF hopes fuel bullish sentiment

    October 12, 2025

    2 Key Indicators Hint Ethereum Could Smash $8K in Q4

    October 11, 2025
    © 2025. coinslopes
    • About Us
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    • Get In Touch

    Type above and press Enter to search. Press Esc to cancel.