DeFi Daily News
Friday, April 10, 2026
Advertisement
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • Altcoins
    • DeFi-IRA
  • DeFi
    • NFT
    • Metaverse
    • Web 3
  • Finance
    • Business Finance
    • Personal Finance
  • Markets
    • Crypto Market
    • Stock Market
    • Analysis
  • Other News
    • World & US
    • Politics
    • Entertainment
    • Tech
    • Sports
    • Health
  • Videos
No Result
View All Result
DeFi Daily News
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • Altcoins
    • DeFi-IRA
  • DeFi
    • NFT
    • Metaverse
    • Web 3
  • Finance
    • Business Finance
    • Personal Finance
  • Markets
    • Crypto Market
    • Stock Market
    • Analysis
  • Other News
    • World & US
    • Politics
    • Entertainment
    • Tech
    • Sports
    • Health
  • Videos
No Result
View All Result
DeFi Daily News
No Result
View All Result
Home DeFi Web 3

rewrite this title Astaroth Banking Trojan Harnessing GitHub to Steal Crypto Credentials – Decrypt

Simon Chandler by Simon Chandler
October 11, 2025
in Web 3
0 0
0
rewrite this title Astaroth Banking Trojan Harnessing GitHub to Steal Crypto Credentials – Decrypt
0
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on Telegram
Listen to this article


rewrite this content using a minimum of 1000 words and keep HTML tags

In brief

McAfee has uncovered a Trojan campaign that uses GitHub to redirect malware to new servers whenever existing servers are taken down.
The malware is primarily targeting countries in South America, with a particular focus on Brazil.
The virus is uploaded via phishing emails, and is capable of stealing banking and crypto credentials.

Hackers are deploying a banking Trojan that makes use of GitHub repositories whenever its servers are taken down, according to research from cybersecurity firm McAfee.

Dubbed Astaroth, the Trojan virus is spread via phishing emails that invite victims to download a Windows (.lnk) file, which installs the malware on a host computer.

Astaroth runs in the background of a victim’s device, using keylogging to steal banking and crypto credentials, and sending such credentials using the Ngrok reverse proxy (an intermediary between servers).

Its unique feature is that Astaroth uses GitHub repositories to update its server configuration whenever its command-and-control server is taken down, which usually happens because of intervention from cybersecurity firms or law enforcement agencies.

“GitHub is not used to host the malware itself, but just to host a configuration that points to the bot server,” said Abhishek Karnik, Director for Threat Research and Response at McAfee.

Speaking to Decrypt, Karnik explained that the malware’s deployers are using GitHub as a resource to direct victims to updated servers, which distinguishes the exploit from previous instances in which GitHub has been harnessed.

This includes an attack vector discovered by McAfee in 2024, in which bad actors inserted the Redline Stealer malware into GitHub repositories, something which has been repeated this year in the GitVenom campaign.

“However, in this case, it’s not malware that is being hosted but a configuration that manages how the malware communicates with its backend infrastructure,” Karnik added.

As with the GitVenom campaign, Astaroth’s ultimate purpose is to exfiltrate credentials that can be used to steal a victim’s crypto or to make transfers out of their bank accounts.

“We don’t have data about how much money or crypto it has stolen, but it appears to be very prevalent, especially in Brazil,” said Karnik.



Targeting South America

It seems that Astaroth has primarily targeted South American territories, including Mexico, Uruguay, Argentina, Paraguay, Chile, Bolivia, Peru, Ecuador, Colombia, Venezuela and Panama.

While it is also capable of targeting Portugal and Italy, the malware is written so that it is not uploaded to systems in the United States or other English-speaking countries (such as England).

The malware shuts down its host system if it detects that analysis software is being operated, while it’s designed to run keylogging functions if it detects that a web browser is visiting certain banking sites.

These include caixa.gov.br, safra.com.br, itau.com.br, bancooriginal.com.br, santandernet.com.br and btgpactual.com.

It has also been written to target the following crypto-related domains: etherscan.io, binance.com, bitcointrade.com.br, metamask.io, foxbit.com.br and localbitcoins.com.

In the face of such threats, McAfee advises that users do not open attachments or links from unknown senders, while also using up-to-date antivirus software and two-factor authentication.

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.

and include conclusion section that’s entertaining to read. do not include the title. Add a hyperlink to this website http://defi-daily.com and label it “DeFi Daily News” for more trending news articles like this



Source link

Tags: AstarothBankingcredentialsCryptoDecryptGithubHarnessingrewriteStealtitletrojan
ShareTweetShare
Previous Post

rewrite this title and make it good for SEO ZORA Doubles After Listing Robinhood and OKX – NFT Plazas

Next Post

rewrite this title Crypto Market Update: Pepeto Advances Presale With Staking Rewards and Live Exchange Demo

Next Post
rewrite this title Crypto Market Update: Pepeto Advances Presale With Staking Rewards and Live Exchange Demo

rewrite this title Crypto Market Update: Pepeto Advances Presale With Staking Rewards and Live Exchange Demo

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Search

No Result
View All Result
  • Trending
  • Comments
  • Latest
rewrite this title Google Unveils Flow: An All-in-One AI Video Editing Tool That Can Do It All!

rewrite this title Google Unveils Flow: An All-in-One AI Video Editing Tool That Can Do It All!

May 21, 2025
rewrite this title How to Get Top Solana Token Holders – Moralis APIs

rewrite this title How to Get Top Solana Token Holders – Moralis APIs

May 14, 2025
rewrite this title and make it good for SEO Hyperliquid Deep Dive: Understand HYPE and HLP Model

rewrite this title and make it good for SEO Hyperliquid Deep Dive: Understand HYPE and HLP Model

April 3, 2025
rewrite this title 10 Tools That Will Give Crypto Traders A Predictive Edge In 2026

rewrite this title 10 Tools That Will Give Crypto Traders A Predictive Edge In 2026

December 14, 2025
Vance, Trump’s VP Choice, Advocates for Stringent China Policy: Analyst Insights – Reuters

Vance, Trump’s VP Choice, Advocates for Stringent China Policy: Analyst Insights – Reuters

July 16, 2024
Finovate announces partnership between InvoiceASAP and Adyen to provide instant payouts

Finovate announces partnership between InvoiceASAP and Adyen to provide instant payouts

August 22, 2024
rewrite this title Iga Swiatek’s new coach brutally slammed by Coco Gauff’s ex-coach & analyst for ‘awful’ decision

rewrite this title Iga Swiatek’s new coach brutally slammed by Coco Gauff’s ex-coach & analyst for ‘awful’ decision

April 9, 2026
rewrite this title Samsung S95H vs. Samsung S95F: I compared the OLED TVs and wasn't prepared for the upset

rewrite this title Samsung S95H vs. Samsung S95F: I compared the OLED TVs and wasn't prepared for the upset

April 9, 2026
rewrite this title Disney’s Paul Roeder Sets Team; April Carretta To Work For Dana Walden

rewrite this title Disney’s Paul Roeder Sets Team; April Carretta To Work For Dana Walden

April 9, 2026
rewrite this title ‘Operation Atlantic’: US and UK Team With Firms to Trace, Freeze Millions in Stolen Crypto – Decrypt

rewrite this title ‘Operation Atlantic’: US and UK Team With Firms to Trace, Freeze Millions in Stolen Crypto – Decrypt

April 9, 2026
rewrite this title with good SEO Rivalry Reignites:  Billion Showdown Unfolds Between Binance And OKX Founders | Bitcoinist.com

rewrite this title with good SEO Rivalry Reignites: $1 Billion Showdown Unfolds Between Binance And OKX Founders | Bitcoinist.com

April 9, 2026
rewrite this title Gusto Acquires Mosey to Add Compliance Capabilities – Finovate

rewrite this title Gusto Acquires Mosey to Add Compliance Capabilities – Finovate

April 9, 2026
DeFi Daily

Stay updated with DeFi Daily, your trusted source for the latest news, insights, and analysis in finance and cryptocurrency. Explore breaking news, expert analysis, market data, and educational resources to navigate the world of decentralized finance.

  • About Us
  • Blogs
  • DeFi-IRA | Learn More.
  • Advertise with Us
  • Disclaimer
  • Privacy Policy
  • DMCA
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact us

Copyright © 2024 Defi Daily.
Defi Daily is not responsible for the content of external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • Altcoins
    • DeFi-IRA
  • DeFi
    • NFT
    • Metaverse
    • Web 3
  • Finance
    • Business Finance
    • Personal Finance
  • Markets
    • Crypto Market
    • Stock Market
    • Analysis
  • Other News
    • World & US
    • Politics
    • Entertainment
    • Tech
    • Sports
    • Health
  • Videos

Copyright © 2024 Defi Daily.
Defi Daily is not responsible for the content of external sites.