Cybercriminals are always looking for new ways to trick people into installing malware. A new campaign discovered in Brazil shows how attackers are now using WhatsApp to spread the well-known Astaroth banking Trojan. Security researchers from Acronis named this campaign Boto Cor-de-Rosa. Instead of sending phishing emails, the attackers use messages that appear to come from someone the victim already knows, making the attack much more convincing.
How the Attack Begins
The infection starts when a user receives a WhatsApp message containing a ZIP archive. Since the message comes from a trusted contact, many users believe it is safe and open the attachment.
After extracting the ZIP file, the victim sees what looks like a normal document or file. However, it is actually an obfuscated Visual Basic Script (VBS). When the user runs this script, it silently downloads additional malware from remote servers. This is the first stage of the attack.
How the Malware Works
The downloaded malware has two main components that work together.
The first component is a Python-based worm module. This module uses WhatsApp Web to access the victim’s contact list. It automatically sends the same malicious ZIP file to every contact, allowing the malware to spread rapidly without requiring the victim to manually send any messages. In many cases, the malware even uses friendly greetings and natural-looking messages to increase the chances that recipients will trust the attachment.

The second component is the Astaroth banking Trojan, whose main payload is written in Delphi. This malware runs quietly in the background and monitors the victim’s web browsing activity. When it detects that the user has opened the website of a bank or financial institution, it becomes active. It can steal usernames, passwords, banking credentials, and other sensitive information. Some variants are also capable of intercepting banking sessions and assisting attackers in performing fraudulent financial transactions.
Technical Features
The attack uses a multi-stage infection chain, making it harder for security software to detect. The initial VBS downloader installs additional files, including an MSI installer, which deploys the malware components on the system. The attackers also bundle a legitimate AutoIt interpreter with encoded files to hide the real malicious payload, helping the malware avoid traditional antivirus detection.
Researchers also found that the malware collects statistics about its own success. It records the number of WhatsApp messages sent, failed delivery attempts, and the speed of message distribution. It can even upload the victim’s contact list to attacker-controlled servers. These features help the attackers measure and improve their campaign over time.
Why Brazil?
More than 95% of the detected infections have been reported in Brazil. WhatsApp is one of the country’s most widely used communication platforms, making it an ideal target for cybercriminals. Only a small number of infections have been reported outside Brazil, including cases in the United States and Austria.
How to Stay Protected
Users should never open ZIP files received unexpectedly, even if they come from a friend or family member. If the message looks unusual, verify with the sender through another communication method before opening the attachment.
Keeping Windows and security software updated, disabling unnecessary script execution, using endpoint protection, and enabling multi-factor authentication (MFA) for banking accounts can significantly reduce the risk of compromise. Organizations should also educate employees about WhatsApp-based phishing attacks and monitor systems for unusual scripting activity involving VBS, PowerShell, Python, or MSI installers.
Conclusion
The Boto Cor-de-Rosa campaign shows that cybercriminals are combining social engineering, automation, and modular malware to make attacks more effective. By using trusted WhatsApp contacts to distribute malicious files automatically, Astaroth has evolved beyond a traditional banking Trojan into a self-spreading threat. This campaign highlights the importance of staying alert, even when messages appear to come from someone you know.

Cyber Security Researcher. Information security specialist, currently working as risk infrastructure specialist & investigator. He is a cyber-security researcher with over 25 years of experience. He has served with the Intelligence Agency as a Senior Intelligence Officer. He has also worked with Google and Citrix in development of cyber security solutions. He has aided the government and many federal agencies in thwarting many cyber crimes. He has been writing for us in his free time since last 5 years.









