Astaroth Information Stealing Trojan
Astaroth is an information stealing trojan that was first observed in 2017 and has continued to evolve over time.
Summary
Astaroth is an information stealing trojan that was first observed in 2017 and has continued to evolve over time.
Affected platforms
The following platforms are known to be affected:
Threat details
This latest version includes several functions to hide it's activity from antivirus defences and in the case of some antivirus software, notably Avast, inject malicious code into it's processes in order to execute further modules.
It is delivered through attachments or malicious hyperlinks emailed to the user as part of spam campaigns.
Once installed upon a machine, depending on the modules downloaded it will; capture keystrokes, system information, clipboard data and gather login passwords for mail accounts and remote computers on the same LAN.
Remediation steps
| Type | Step |
|---|---|
|
To prevent and detect a trojan infection, ensure that:
|
Last edited: 14 February 2020 2:51 pm