Skip to content

Bitcoin Trojan Exploits GitHub for Crypto Theft

Astaroth Trojan Uses GitHub for Resilience in Crypto Credential Theft

  • The Astaroth Trojan campaign uses GitHub to redirect malware to new servers when existing ones are taken down.
  • This malware primarily targets South American countries, especially Brazil, through phishing emails.
  • Astaroth steals banking and crypto credentials using keylogging and Ngrok reverse proxy techniques.
  • It targets specific banking sites like caixa.gov.br and crypto-related domains such as binance.com and etherscan.io.

Astaroth leverages GitHub repositories to update its server configuration, enhancing its resilience against cybersecurity interventions. This method distinguishes it from previous exploits that hosted malware directly on platforms like GitHub.

The campaign’s focus on stealing credentials from targeted regions highlights the need for vigilance against phishing attacks and the importance of using up-to-date antivirus software and two-factor authentication. (Source)

Share