Guildma

Malware updated 4 months ago (2024-05-04T23:18:27.902Z)
Download STIX
Preview STIX
Guildma is a malicious software (malware) that has been operational since at least 2015, initially targeting banking users exclusively from Brazil. Over time, this malware, alongside others such as Javali, Melcoz, and Grandoreiro, expanded its operations to target banks in other countries including Chile, Uruguay, Peru, Ecuador, Colombia, China, Europe, and of course, Brazil. The malware is known for its deceptive tricks, using various processes like ExtExport.exe related to Internet Explorer, and in more recent campaigns, leveraging YouTube for hosting Command and Control (C2) information. Guildma's intended targets can be discerned from its code, revealing its capacity to steal data from bank customers living in these regions. The evolution of Guildma has seen it adopt more sophisticated techniques over the years. By the end of September 2019, a new version of the Guildma malware was identified, which used a novel technique for storing downloaded payloads in NTFS Alternate Data Streams, effectively concealing their presence in the system. Furthermore, the newer versions of Guildma found in 2020 employed an automated process to generate thousands of daily URLs, primarily exploiting generic Top-Level Domains (TLDs). This innovation allowed the malware to maintain its efficacy while making detection and mitigation efforts more challenging. Guildma spreads primarily through email shots containing a malicious file in compressed format, attached to the email body. Upon further examination of the delivered trojans, it was discovered that more than 300 financial organizations have already fallen victim to the Astaroth trojan, also known as Guildma. As a result, Guildma poses a significant threat to both individuals and organizations globally, necessitating robust cybersecurity measures to prevent its spread and mitigate its impact.
Description last updated: 2024-05-04T22:53:09.758Z
What's your take? (Question 1 of 0)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Trojan
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the Guildma Malware was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
CERT-EU
7 months ago
High-volume malware campaigns involve Google Cloud Run exploitation
MITRE
2 years ago
The Tetrade: Brazilian banking malware goes global
CERT-EU
a year ago
InfoSec Handlers Diary Blog - SANS Internet Storm Center