Guildma Remote Access Trojan
Guildma is a modular remote access trojan targeting financial and governmental organisations. First observed in 2015 in campaigns primarily targeting South America, Guildma began to see use in global campaigns starting in May 2019.
Summary
Guildma is a modular remote access trojan targeting financial and governmental organisations. First observed in 2015 in campaigns primarily targeting South America, Guildma began to see use in global campaigns starting in May 2019.
Affected platforms
The following platforms are known to be affected:
Threat details
The majority of Guildma campaigns begin with a spam email containing a ZIP archive file attachment, although it is not uncommon for campaigns to use sophisticated spear-phishing tactics to compromise specific targets. These attachments contain a malicious LNK file which, when opened, invoke the Windows Management Instrumentation Command-line (WMIC) tool to download an XSL file. This XSL file is then used to download Guildma's individual modules and to execute a first-stage loader, which will then install the modules.
Once installed, Guildma will collect user and system information to send back to a command and control server, before awaiting further commands. By default, it has the ability to monitor email and messaging applications, record audio and video, steal account credentials, and install secondary payloads. Guildma will also monitor user browser activity and attempt to phish their information whenever they visit banking related websites.
Remediation steps
| Type | Step |
|---|---|
|
To prevent and detect a trojan infection, ensure that:
|
Last edited: 14 February 2020 2:50 pm