Listen to the episode
TLDR
SANS ISC handler Russ McRee reports an active Guildma (Astaroth) malware campaign delivered through Brazilian Portuguese language phishing emails. The messages impersonate legitimate notifications, often appearing to be invoices, tax...
How it works
SANS ISC handler Russ McRee reports an active Guildma (Astaroth) malware campaign delivered through Brazilian Portuguese language phishing emails. The messages impersonate legitimate notifications, often appearing to be invoices, tax...
Red flags
- Unexpected email in Portuguese (or any language you do not normally use at work) with attachments or download links. Pressure to open an invoice, fiscal receipt, or court notice immediately. Attachments with double extensions (e.g., .pdf.exe , .html.js ) or links to cloud storage downloads
What to do
- 1Do not open attachments or click links from unsolicited Portuguese language emails
- 2verify with the sender via a known channel. Block and quarantine the message, then report it to your IT/security team
Source
FAQ
Is Guildma Astaroth malware spreads via Brazilian Portuguese phishing emails a real scam pattern?
Yes. Treat the message, call, or payment request as suspicious until you verify it through an official channel.
What are the first warning signs?
Unexpected email in Portuguese (or any language you do not normally use at work) with attachments or download links. Pressure to open an invoice, fiscal receipt, or court notice immediately. Attachments with double extensions (e.g., .pdf.exe , .html.js ) or links to cloud storage downloads
What should I do first?
Do not open attachments or click links from unsolicited Portuguese language emails; verify with the sender via a known channel. Block and quarantine the message, then report it to your IT/security team
Can LegalAudit check my case?
Yes. Start a free chat and paste the message, link, sender, or payment details for triage.