Close Menu
CoinailsCoinails

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    ETH And BTC Holders Are Flocking To OAK Mining For Stable Profits Of $8,600 Daily

    October 16, 2025

    What the Trial Related to a MEV Bot Exploit Means for the Industry

    October 15, 2025

    Bitcoin ‘still qualifies’ for debasement trade as gold towers to fresh record, analysts say – DL News

    October 15, 2025
    Facebook X (Twitter) Instagram
    Trending
    • ETH And BTC Holders Are Flocking To OAK Mining For Stable Profits Of $8,600 Daily
    • What the Trial Related to a MEV Bot Exploit Means for the Industry
    • Bitcoin ‘still qualifies’ for debasement trade as gold towers to fresh record, analysts say – DL News
    • NFT Market Rebounds After $1.2B Wipeout in Friday’s Crypto Crash
    • CryptoMondays Global Multi-City Meetups Throughout October
    • These 4 Drivers Could Push DASH to $100 Soon
    • Morpho price outlook: why bulls are locked on breakout above $2
    • BNB Price Chart Flashing Bullish Signal: $4,500 Ahead?
    Facebook X (Twitter) Instagram Pinterest Vimeo
    CoinailsCoinails
    • Home
    • Altcoins
    • Press Release
    • Bitcoin News
    • NFT Trends
    • DeFi Insights
      • Ethereum Updates
    • Web3 Technology
      • Crypto Regulations
    CoinailsCoinails
    Home»Bitcoin News»Astaroth Banking Trojan Harnessing GitHub to Steal Crypto Credentials
    Bitcoin News

    Astaroth Banking Trojan Harnessing GitHub to Steal Crypto Credentials

    adminBy adminOctober 11, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Decrypt logo
    Share
    Facebook Twitter LinkedIn Pinterest Email

    In brief

    • McAfee has uncovered a Trojan campaign that uses GitHub to redirect malware to new servers whenever existing servers are taken down.
    • The malware is primarily targeting countries in South America, with a particular focus on Brazil.
    • The virus is uploaded via phishing emails, and is capable of stealing banking and crypto credentials.

    Hackers are deploying a banking Trojan that makes use of GitHub repositories whenever its servers are taken down, according to research from cybersecurity firm McAfee.

    Dubbed Astaroth, the Trojan virus is spread via phishing emails that invite victims to download a Windows (.lnk) file, which installs the malware on a host computer.

    Astaroth runs in the background of a victim’s device, using keylogging to steal banking and crypto credentials, and sending such credentials using the Ngrok reverse proxy (an intermediary between servers).

    Its unique feature is that Astaroth uses GitHub repositories to update its server configuration whenever its command-and-control server is taken down, which usually happens because of intervention from cybersecurity firms or law enforcement agencies.

    “GitHub is not used to host the malware itself, but just to host a configuration that points to the bot server,” said Abhishek Karnik, Director for Threat Research and Response at McAfee.

    Speaking to Decrypt, Karnik explained that the malware’s deployers are using GitHub as a resource to direct victims to updated servers, which distinguishes the exploit from previous instances in which GitHub has been harnessed.

    This includes an attack vector discovered by McAfee in 2024, in which bad actors inserted the Redline Stealer malware into GitHub repositories, something which has been repeated this year in the GitVenom campaign.

    “However, in this case, it’s not malware that is being hosted but a configuration that manages how the malware communicates with its backend infrastructure,” Karnik added.

    As with the GitVenom campaign, Astaroth’s ultimate purpose is to exfiltrate credentials that can be used to steal a victim’s crypto or to make transfers out of their bank accounts.

    “We don’t have data about how much money or crypto it has stolen, but it appears to be very prevalent, especially in Brazil,” said Karnik.

    Targeting South America

    It seems that Astaroth has primarily targeted South American territories, including Mexico, Uruguay, Argentina, Paraguay, Chile, Bolivia, Peru, Ecuador, Colombia, Venezuela and Panama.

    While it is also capable of targeting Portugal and Italy, the malware is written so that it is not uploaded to systems in the United States or other English-speaking countries (such as England).

    The malware shuts down its host system if it detects that analysis software is being operated, while it’s designed to run keylogging functions if it detects that a web browser is visiting certain banking sites.

    These include caixa.gov.br, safra.com.br, itau.com.br, bancooriginal.com.br, santandernet.com.br and btgpactual.com.

    It has also been written to target the following crypto-related domains: etherscan.io, binance.com, bitcointrade.com.br, metamask.io, foxbit.com.br and localbitcoins.com.

    In the face of such threats, McAfee advises that users do not open attachments or links from unknown senders, while also using up-to-date antivirus software and two-factor authentication.

    Daily Debrief Newsletter

    Start every day with the top news stories right now, plus original features, a podcast, videos and more.

    Astaroth Banking Credentials Crypto GitHub Harnessing Steal Trojan
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleRipple Reverses 40% Losses After Its Worst Crash
    Next Article Senate Passes GAIN Act as Part of 2026 National Defense Authorization Bill
    admin
    • Website

    Related Posts

    NFT Trends

    NFT Market Rebounds After $1.2B Wipeout in Friday’s Crypto Crash

    October 15, 2025
    Bitcoin News

    BNB Price Chart Flashing Bullish Signal: $4,500 Ahead?

    October 15, 2025
    NFT Trends

    How to Use Google Gemini to Analyze Crypto Coins Before Investing

    October 14, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Metaplanet (MTPLF) Hits Pause Button on Share Sales

    October 11, 20252 Views

    SharpLink’s ETH Treasury Surpasses $900M in Unrealized Gains

    October 9, 20252 Views

    Grayscale Enables Staking For First US Spot Crypto ETPs

    October 9, 20252 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    Press Release

    ETH And BTC Holders Are Flocking To OAK Mining For Stable Profits Of $8,600 Daily

    adminOctober 16, 2025
    Ethereum Updates

    What the Trial Related to a MEV Bot Exploit Means for the Industry

    adminOctober 15, 2025
    DeFi Insights

    Bitcoin ‘still qualifies’ for debasement trade as gold towers to fresh record, analysts say – DL News

    adminOctober 15, 2025

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    Metaplanet (MTPLF) Hits Pause Button on Share Sales

    October 11, 20252 Views

    SharpLink’s ETH Treasury Surpasses $900M in Unrealized Gains

    October 9, 20252 Views

    Grayscale Enables Staking For First US Spot Crypto ETPs

    October 9, 20252 Views
    Our Picks

    BC.GAME News Backs Deccan Gladiators As Title Sponsor In 2025 Abu Dhabi T10 League

    October 7, 2025

    Cango Inc. Announces September 2025 Bitcoin Production And Mining Operations Update

    October 7, 2025

    Swiss Regulator Investigates FIFA’s Blockchain Ticket Tokens for Possible Gambling Violations

    October 7, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    © 2025 coinails.com

    Type above and press Enter to search. Press Esc to cancel.