Guildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st)
2026-09-01T01:23:41Z•f092cfbb4a580c5522446b9f40850203c67d0d962da1d19fd99a125d98f2303d
AstarothBrazilian PortugueseEntra IDGuildmaLLM securityYARA-Xcoding-agent securitydata exposureemail threathoneypotidentity governancemalicious PEmalwarephishingpolymorphic phishingprivileged access
What happened
SANS Internet Storm Center digest covering Guildma/Astaroth malware delivered through Brazilian Portuguese email, phishing campaigns including polymorphic pages, exposure risks from malicious operators abusing free LLM endpoints and coding-agent data, Entra ID administrative privilege governance, malicious PE metadata analysis, and YARA-X updates. The most direct active-threat item is a phishing-led Guildma/Astaroth infection; the LLM honeypot report highlights potential credential, filesystem, path, and tool-manifest disclosure risks.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- f092cfbb4a580c5522446b9f40850203c67d0d962da1d19fd99a125d98f2303d
- Enrichment time
- 2026-09-01T01:23:41Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.