Guildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st)

2026-09-01T01:23:41Zf092cfbb4a580c5522446b9f40850203c67d0d962da1d19fd99a125d98f2303d
AstarothBrazilian PortugueseEntra IDGuildmaLLM securityYARA-Xcoding-agent securitydata exposureemail threathoneypotidentity governancemalicious PEmalwarephishingpolymorphic phishingprivileged access

What happened

SANS Internet Storm Center digest covering Guildma/Astaroth malware delivered through Brazilian Portuguese email, phishing campaigns including polymorphic pages, exposure risks from malicious operators abusing free LLM endpoints and coding-agent data, Entra ID administrative privilege governance, malicious PE metadata analysis, and YARA-X updates. The most direct active-threat item is a phishing-led Guildma/Astaroth infection; the LLM honeypot report highlights potential credential, filesystem, path, and tool-manifest disclosure risks.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
f092cfbb4a580c5522446b9f40850203c67d0d962da1d19fd99a125d98f2303d
Enrichment time
2026-09-01T01:23:41Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.