Astaroth has added a new way to spread, turning a victim’s WhatsApp Web session into a delivery channel for the same malware. The banking trojan sends convincing messages and a malicious ZIP attachment to people in the user’s own contact list, exploiting trust in familiar senders. This gives attackers a faster route into personal and business conversations. Earlier campaigns relied mainly on phishing emails and shortcut files that launched a hidden infection chain on Windows. The new component shifts delivery to WhatsApp Web, allowing the operation to move from one compromised account to many contacts without the attacker writing every message. For recipients, the familiar sender can lower suspicion and raise the odds...
Read the full article at the source.
Comments (0)
No comments yet. Be the first to comment!