The Ultimate Guide To Cybersecurity In The Real World. - Register Here
The Ultimate Guide To Cybersecurity In The Real World. - Register Here
Schedule a Consultation
Hoplon InfoSec Logo
  • Products
  • Services

Hoplon Infosec · Threat Intelligence

Astaroth Malware Attack 2025: How Cybercriminals Are Using GitHub to Steal Your Banking Data

ByRadia
Published25 Mar, 2026
Astaroth Malware Attack 2025: How Cybercriminals Are Using GitHub to Steal Your Banking Data
Radia25 Mar, 2026

Do you ever feel like someone is watching you, even while you're alone? The Astaroth virus attack in 2025 resembles that feeling, but it occurs online. Picture someone you can't see sitting next to your computer and discreetly watching every click, every password you write, and every time you go to your bank or crypto wallet. That's Astaroth, and it's smart. Very clever. It's now hiding on GitHub, a site that most of us trust totally.

Digital banking and cryptocurrency wallets have definitely made things easier. But there is a cost to being easy. Cybercriminals have used that ease to make malware like Astaroth. It waits and watches in silence, then attacks at the proper time.

How Astaroth Gets In


Most attacks start with something that seems innocent, like an email that is well-written. It can look like it originated from your bank, a well-known service, or even a job application. If you click on the wrong thing or open a zip file, Astaroth will discreetly install itself on your machine.

I read about a Brazilian company that lends money. A worker opened an invoice that seemed normal. Things started to happen that were unusual hours later. But the IT team always found that everything was alright. That's what makes Astaroth so brilliant and scary. It hides in plain sight, waiting to take your banking or cryptocurrency logins when you least expect it.

GitHub is a backup.

This is the bit that really caught my eye. Astaroth now uses GitHub as a backup instead of merely servers that can be shut down. GitHub is where the malware receives its configuration files. It also hides its instructions in conventional photographs using a technology called steganography. Security systems don't monitor GitHub content very regularly, so it stays running in the background even when the main servers go down.

This isn't the kind of spyware you see all the time. It's quite hard to get rid of the Astaroth virus attack from 2025. After McAfee alerted GitHub about the rogue repositories, the company's security staff took them down. For a short time, this stopped the attack. But the way the malware was built illustrates how far hackers have progressed in turning trusted platforms into covert weapons.

spyware Attack Process

Screenshot 2025-10-13 162914

The Chain of Infection

This is how it generally works:

  • You get an email that seems like a scam to steal your information.

  • When you open the zip file that is attached, it installs a Windows shortcut file (.lnk) that launches scripts without your knowledge.

  • • The script combines elements of the payload in memory, making it hard to find.

  • The spyware watches your browser windows for sites that deal with banking or cryptocurrencies.

  • It records what you type and transfers it to the attackers using secure channels.

  • It continuously checks GitHub for fresh instructions in the meantime, which makes the assault more flexible.
    Most antivirus programs can't find it because it largely runs in memory.

    Who is at risk?

    People that have cryptocurrencies and utilize online banking are the most likely to be targeted. Most of the attacks have happened in Brazil, Mexico, and other South American countries, but they might happen anywhere in the world. People who use bitcoins are considerably more in danger. Once Astaroth has your keys, getting your money back is almost impossible.

    You may call it a master key maker. It not only makes copies of your keys, but it also hides them in secret places so that it can always get in, even if you "change the locks."

    Staying Safe

    You can't get rid of all the hazards, but you can make them smaller:

  • Don't open attachments or respond to emails from persons you don't know.

  • Whenever you can, use two-factor authentication (2FA).

  • Always keep your antivirus and security programs up to date.

  • Watch what your network is doing, especially when you utilize sites like GitHub.

  • Be wary and ask questions about anything that seems weird online.

Astaroth C2 & config below

Astaroth malware attack 2025

Source: McAfee


The Technical Side

Astaroth targets popular browsers and apps. It watches sites like caixa.gov.br, safra.com.br, and itau.com.br and crypto platforms like binance.com and metamask.io. The attackers obtain the stolen data using encrypted methods, and the virus updates itself every few hours from GitHub sources. This combination of outdated servers with GitHub makes it quite powerful.

Technical Breakdown

Astaroth malware attack 2025

Source: McAfee

The Hoplon Insight Box

Be careful: Don't open emails or attachments that seem strange.

Behavior-Based Security: Always watch your devices.

Check Sources: You should always check files that other people send you.

Turn on 2FA to make your accounts safer.

If something doesn't seem right, tell the IT or security teams.

Source

Hoplon Infosec's Endpoint Security solution helps keep your devices safe from dangers like the Astaroth malware attack in 2025. It searches for unusual behavior, stops malware right away, and makes sure that important data is safe before any harm can be done.

Follow us on X (Twitter) and LinkedIn for more cybersecurity news and updates. Stay connected on YouTube, Facebook, and Instagram as well.

About the author

R

Radia

Was this useful?

React, leave a note, or share it forward.

Leave a note

Share this article

Share this :

Free · Weekly · No noise

Get the threats that matter, before they reach you.

One short email a week with the breaches, zero-days, and fixes worth your attention — written in plain English, no fear-mongering.

Hoplon InfoSec Logo
Address : 1415 West 22nd Street, Tower Floor, Oak Brook, IL 60523

Phone : +1 (773) 904-3136

Email : info@hoploninfosec.com

Services

  • Penetration Testing
  • Cyber Security Assessment
  • AI Development
  • Incident Readiness & Response Recovery

Products

  • IBM Flash Storage Solutions
  • Mobile Security
  • Endpoint Security
  • Deep and Dark Web Monitoring

Sign Up For Newsletter

Get the latest updates on new products and upcoming news

Copyright © Hoplon InfoSec, LLC and its group of companies.
About usContact usTerms & ConditionsCookie PolicyPrivacy Policy
03Latest posts

Keep reading.

SonicWall SMA1000 Zero-Day Vulnerabilities: Patch Now
15 Jul, 2026

SonicWall SMA1000 Zero-Day Vulnerabilities: Patch Now

SonicWall SMA1000 zero-day vulnerabilities are under active attack. See affected versions, CVE details, IOC checks and the patch you need right now.

Read More
Windows 11 KB5101650 Dell Issue: Causes and Full Fix Guide
15 Jul, 2026

Windows 11 KB5101650 Dell Issue: Causes and Full Fix Guide

Windows 11 KB5101650 is blocked on some Dell PCs after an Intel driver conflict triggered shutdowns and overheating. Here is what happened and what to do.

Read More
OFAC Sanctions First VPN Service Over Ransomware
14 Jul, 2026

OFAC Sanctions First VPN Service Over Ransomware

Learn why OFAC sanctioned First VPN Service and a malware cryptor seller, how 1VPNS helped ransomware groups, and how to defend against FSB router attacks.

Read More
CVE-2026-57807: Critical WordPress SSO Flaw Explained
13 Jul, 2026

CVE-2026-57807: Critical WordPress SSO Flaw Explained

CVE-2026-57807 affects miniOrange OAuth SSO through 38.5.8. Learn who is exposed, how the flaw works, plus safe mitigation and incident response steps.

Read More
Mobile App Security Guide: Risks, Fixes and Best Practices
13 Jul, 2026

Mobile App Security Guide: Risks, Fixes and Best Practices

Mobile app security explained simply, covering real risks, OWASP threats, encryption and practical steps to protect any app from hackers.

Read More
Apple OpenAI Lawsuit: Inside the Trade Secret Theft Claims
13 Jul, 2026

Apple OpenAI Lawsuit: Inside the Trade Secret Theft Claims

Apple OpenAI lawsuit explained. See what Apple accuses Tang Tan, Chang Liu and OpenAI of stealing, and what it means for hardware security.

Read More