This week, Tanium’s Cyber Threat Intelligence (CTI) team examines Astaroth, an advanced banking trojan targeting users in South America. Our team also provide an update on TA585, a sophisticated threat actor that controls its entire attack chain and frequently deploys MonsterV2 malware. Finally, we explore how threat actors exploit Microsoft’s trusted branding in advanced tech support scams.
Astaroth trojan uses GitHub to host malware configurations
McAfee is sharing details about Astaroth, a sophisticated banking trojan that steals credentials by keylogging when users access banking or cryptocurrency websites.
What makes this variant particularly resilient is its use of GitHub repositories to host malware configurations and bypass traditional command-and-control (C2) server takedowns.
Astaroth’s phishing email
This attack starts with a phishing email containing a link that downloads of a ZIP file when clicked. According to McAfee, the lures in these emails often relate to DocuSign links and resumes.
The downloaded ZIP file contains an LNK file further containing an obfuscated JavaScript command. McAfee reports that each link is geo-restricted.
The downloaded JavaScript will download several files from a randomly selected server. The downloaded files include an AutoIt compiled script, AutoIt interpreter, encrypted payload, and an encrypted malware configuration. JavaScript will execute the AutoIt script to load shellcode in-memory.
Payload analysis
Astaroth is the payload in this campaign. The malware is written in Delphi and will shut down the system if it believes it is being analyzed. It will check for the existence of several tools on the system, ensure the system locale is related to the U.S., and continuously check for open browsers. The malware will hook keyboard events and gather keystrokes if it identifies a banking related site or cryptocurrency site is opened.
C2 communication and infrastructure
The stolen credentials are sent to the attacker’s C2 server using a custom binary protocol.
McAfee notes that the configuration is updated every two hours. It performs this update by “fetching an image file from config update URLs and extracting the hidden configuration from the image.” The configuration file is hidden because of the format it is stored in. McAfee identified several GitHub repositories that had image files with the same pattern, all of which have since been taken down.
For persistence, Astaroth drops an LNK file that will execute at startup and will run the AutoIt script to trigger the malware at system start.
Analyst comments from Tanium’s Cyber Threat Intelligence team
Attackers are increasingly exploiting trusted platforms to evade detection. This particular actor is taking extra steps to blend its malware into normal traffic by embedding data in images, making it more difficult for defenders to spot anomalies.
This is currently very tailored and targeted, and specifically excludes systems with locales related to the U.S., though its techniques are globally applicable.
TA585 delivers MonsterV2 malware in phishing campaigns
Proofpoint recently published research about TA585, a sophisticated threat actor that controls its entire attack chain and frequently deploys the powerful MonsterV2 malware to steal credentials, perform surveillance, and deliver additional payloads.
[Learn how access control strengthens security and helps protect your organization]
According to Proofpoint, TA585 uses deceptive lures, advanced social engineering, and infrastructure like ClickFix and CoreSecThree to evade detection and maximize impact.
Campaign details
TA585 will typically distribute malware via compromised websites, which often display a fake CAPTCHA to the victim. If the victim executes the copied script, the malware is then downloaded.
Proofpoint also observed the actor’s malware payloads being delivered via emails instead of fake CAPTCHA page websites. These emails were primarily notifications from GitHub where the actor tagged GitHub users in fake security notices. Other researchers have also observed the actor delivering malware via malvertising.
More CAPTCHA threats in the news
Over the past few months, CAPTCHA-related threats have continued to evolve, becoming more sophisticated and integrated into phishing, malware delivery, and credential theft campaigns.
Here are four notable reports from our recent research:
1. ClickFix resurgence: Get an in-depth analysis about the return of ClickFix in advanced threat campaigns exploiting CAPTCHA for stealth and persistence.
2. ClickFix campaign hijacks CAPTCHAs: Explore how attackers are leveraging CAPTCHA bypass techniques in evolving campaigns.
3. Fake CAPTCHA pages in UNC5518 campaigns: Learn how UNC5518 uses CORNFLAKE.V3 with ClickFix for obfuscation.
4. CAPTCHA in AI-obfuscated phishing: See how CAPTCHA is being used to mask phishing operations and malware delivery.
About MonsterV2 malware
MonsterV2 acts as both a stealer and a loader, often dropping additional malware such as StealC. Other actors are also using MonsterV2 malware. Proofpoint first came across MonsterV2 in February 2025 when they observed it in a campaign that used IRS-related lures.
According to Proofpoint, the malware comes equipped with several capabilities including the ability to enumerate and exfiltrate login data, tokens, browser data, files, etc. It can also record the victim’s webcam, view the desktop, comes with clipper capabilities, download and execute further payloads and much more. Proofpoint also found that the malware will avoid infecting CIS countries. The malware is being actively maintained and updated.
At initialization, the malware will try to elevate its privileges and then create a mutex on the system. It will then decrypt and decompress its config and reach out to a domain to obtain the infected systems IP and location before reaching out to its C2 server.
MonsterV2 and SonicCrypt crypter
Proofpoint determined that MonsterV2 malware is usually packed using SonicCrypt crypter. Malware packed by SonicCrypt intentionally contains a large volume of junk code to make analysis more difficult. Before loading its payload, SonicCrypt will run through a few anti-analysis checks and then write it to a file on disk and execute the payload.
Analyst comments from Tanium’s Cyber Threat Intelligence team
TA585 avoids CIS countries and uses geofencing during malware deployments, which may indicate regional alliances or an attempt to avoid local law enforcement.
The actor’s full-stack control over its attack infrastructure from delivery to payload demonstrates an interesting twist in which the actor is looking to reduce its reliance on third-party services. This is different than the current trend of actors leveraging third-party services to blend in.
Threat actors exploit Microsoft’s logo in tech support scams
According to Cofense, threat actors are exploiting Microsoft’s trusted branding to execute advanced tech support scams.
The attack begins with a payment lure email, redirecting victims through a fake CAPTCHA to a browser-locking page filled with fraudulent Microsoft security alerts and coercing users into calling a fake support number. Once on the call, attackers attempt to harvest credentials or install remote access tools.
This scam is like others in circulation. However, this scam combines social engineering with fake system alerts and UI overlays, which makes it more comprehensive and dangerous.
Attack overview
The email in this campaign uses typical scam tactics related to financial gain and banking to lure victims. It pretends to be a reimbursement or payment from a rental car company and asks the recipient to confirm their email to receive the funds.
If the victim clicks on the button to confirm their email, they are led to a fake CAPTCHA page to complete a verification. After verifying they are human, the victim is redirected again to the true landing page. This landing page is where the campaign goes beyond traditional scam methods.
Once on the landing page, the victim will see several popups pretending to be Microsoft security alerts. The browser is manipulated to appear locked, and the user loses the ability to locate or control their mouse. This lock is an illusion and can be circumvented simply by holding down the ESC key.
The attack leans on the familiarity of Microsoft’s branding, logo, terminology, and alert style to trick the victim into calling the fake Microsoft Support phone number.
Analyst comments from Tanium’s Cyber Threat Intelligence team
This campaign simulates a ransomware experience by “locking” the browser, and forcing victims into panicking and making snap decisions. It also uses Microsoft branding to exploit years of user trust, along with a fake CAPTCHA to further persuade the user into thinking the activity is legitimate.
As a result, this campaign has the potential to be more successful than traditional tech support scams.
Do you have insight into these stories that you want to share? Head over to Tanium’s discussion forum to start a conversation.
For further reading, catch up on our recent cyber threat intelligence roundups.
