Published Security3 min read
Astaroth Now Spams From Your Contacts List, Not Your Inbox
CrowdStrike says the Brazil-focused banking trojan added a headless WhatsApp Web spambot in Q4 2025 that messages every contact a victim has. The propagation path no longer touches an email gateway.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- In Q4 2025, the Astaroth installer's command-and-control servers began distributing an additional, previously unidentified component: a WhatsApp Web spambot.
- In Q4 2025, operators of the Astaroth (aka Guildma) botnet introduced a previously unidentified capability: a WhatsApp Web spambot component designed to turn victims into unwitting distributors of the malware by automatically messaging every contact in each victim's WhatsApp contact list.
- CrowdStrike describes the WhatsApp Web spambot as a significant shift from Astaroth's traditional email-based spam propagation to a distribution method using trusted social messaging platforms.
- By running a browser instance in headless mode and stripping automation indicators from a WebDriver session, the spambot conducts its entire spam campaign without ever displaying a browser window to the victim.
- Identical function names, variable names, file delivery logic, contact-filtering implementations, and configuration field-naming conventions confirm a strong developmental relationship between the Astaroth spambot and a spambot dubbed Vareg (aka WATER SACI, Eternidade), which previously distributed other LATAM banking trojans via WhatsApp Web in October 2025 and November 2025 campaigns.
Compiled by The WatchSomething wrong?How this is made
Why it matters
CrowdStrike reports that in Q4 2025 the command-and-control servers behind the Astaroth installer began delivering a component the company had not previously identified: a WhatsApp Web spambot that automatically messages every contact in an infected victim's WhatsApp contact list [1][2]. CrowdStrike characterises this as a significant move away from the group's traditional email-based spam propagation toward distribution over trusted social messaging platforms [3].
The mechanics matter more than the label. According to CrowdStrike, the spambot runs a browser instance in headless mode and strips automation indicators from a WebDriver session, so the entire spam campaign completes without a browser window ever appearing on the victim's screen [4]. The victim is not tricked into forwarding anything. Their authenticated session does the sending, which means the recipient sees a message from a known contact rather than an unfamiliar sender address.
That is the part worth sitting with. Propagation now happens inside a messaging session on the endpoint, so an email security gateway is not in the delivery path at all and has nothing to inspect [1]. Of the behaviours CrowdStrike describes, the observable ones are host-side: a headless browser process and a WebDriver session with its automation flags removed [2].
The component did not appear from nowhere. CrowdStrike says identical function names, variable names, file delivery logic, contact-filtering implementations, and configuration field-naming conventions confirm a strong developmental relationship between the Astaroth spambot and a spambot it tracks as Vareg, also known as WATER SACI and Eternidade, which distributed other LATAM banking trojans via WhatsApp Web in October 2025 and November 2025 campaigns [5]. Those months sit inside the same quarter in which Astaroth adopted the technique [3], so this is shared tooling moving between contemporaneous operations rather than an old capability being dusted off.
Targeting stays narrow. CrowdStrike cites Brazil-specific phone number filtering, Portuguese-language spam templates, and language-oriented HTTP headers as indicators that the operators are pursuing Brazil-based victims [6], consistent with its assessment that Astaroth now exclusively targets users in Brazil [7]. The malware itself is not new: CrowdStrike dates it to at least 2015 [7], which makes it a decade-old family adding a new distribution arm rather than a fresh entrant [4].
The infection chain in front of the spambot is unchanged. CrowdStrike describes delivery via a downloader script, often a Windows shortcut file running JScript, which retrieves an installer; the installer runs an AutoIt-based loader that decodes and executes a Delphi-based loader DLL in memory, and that DLL decrypts and executes the core component [8]. The spambot arrives as an additional payload from that same installer infrastructure [1], which means every existing infection is a candidate distributor without the operators touching the front door.
Watch whether the Vareg codebase surfaces in further LATAM families, since shared function and configuration naming is the kind of overlap that tends to spread once it works [5]. Watch whether the Brazil-only phone number filtering loosens, which would be the first signal that this technique is being aimed outside Portuguese-speaking targets [6]. And watch how many organisations discover that their inbound malware controls were the only ones they had.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
In Q4 2025, the Astaroth installer's command-and-control servers began distributing an additional, previously unidentified component: a WhatsApp Web spambot.
- [2]
In Q4 2025, operators of the Astaroth (aka Guildma) botnet introduced a previously unidentified capability: a WhatsApp Web spambot component designed to turn victims into unwitting distributors of the malware by automatically messaging every contact in each victim's WhatsApp contact list.
- [3]
CrowdStrike describes the WhatsApp Web spambot as a significant shift from Astaroth's traditional email-based spam propagation to a distribution method using trusted social messaging platforms.
- [4]
By running a browser instance in headless mode and stripping automation indicators from a WebDriver session, the spambot conducts its entire spam campaign without ever displaying a browser window to the victim.
- [5]
Identical function names, variable names, file delivery logic, contact-filtering implementations, and configuration field-naming conventions confirm a strong developmental relationship between the Astaroth spambot and a spambot dubbed Vareg (aka WATER SACI, Eternidade), which previously distributed other LATAM banking trojans via WhatsApp Web in October 2025 and November 2025 campaigns.
- [6]
Multiple technical indicators, including Brazil-specific phone number filtering, Portuguese-language spam templates, and specific language-oriented HTTP headers, confirm Astaroth's operators are targeting Brazil-based victims.
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- crowdstrike.comKevin RattoInside Astaroth's New Spambot Component
Additional citations
- CrowdStrike



