Guildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st)

2026-09-02T01:23:40Zf4c94d1c0d72d36295429b3455181a309894b3a0624cd1a503cd45a3d54e3215
AstarothBrazilian PortugueseEntra IDGuildmaLLM securityYARA-Xcoding-agent securityemail-borne malwarehoneypotidentity and access managementmalicious PEmalwarephishingpolymorphic phishing

What happened

SANS Internet Storm Center feed containing reports on Guildma (Astaroth) malware delivered through Brazilian Portuguese phishing email, polymorphic phishing pages, malicious PE-file characteristics, and risks from internet-exposed LLM inference endpoints leaking coding-agent sessions and local environment data. It also includes defensive content on Entra ID administrative privileges and a YARA-X release. The primary security-relevant item is an active malware/phishing campaign involving Guildma/Astaroth.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
f4c94d1c0d72d36295429b3455181a309894b3a0624cd1a503cd45a3d54e3215
Enrichment time
2026-09-02T01:23:40Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Guildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st) · Baitaphish