Red Mosquito - Blog

Microsoft Warning on Astaroth Malware

19 Jul 2019

Microsoft has recently issued a security  warning.  Their Windows Defender ATP team have discovered hackers are distributing Astaroth malware using fileless techniques.  This makes Astaroth very difficult to detect as traditional anti-malware or anti-virus software tools search for infected files.  So, they would not catch Astaroth, simply because it does not infect files.    Astaroth malware is spread through a huge spam email campaign.  The emails contain a link to a website, which if you double- clicked, would run legitimate Windows tools.  These are then used to download and communicate additional code, without saving any files.  The attack ends with the Astaroth Trojan being downloaded.  At this point, it would collect sensitive data and upload it to a remote server.   This technique is know as “living off the land” as it uses existing system tools to do all the work.

It’s worth noting that the majority of these attacks are discovered in Brazil and the URL received in the initial email uses some Portuguese terminology ie certida.htm (Portuguese for certificate), abrir_documento.htm (open document), pedido.htm (order).

What can you do to protect your system against attack?

Although challenging to detect, these fileless threats are not invisible. Microsoft advice is to make sure your Windows 10 and Windows Defender Firewall are up to date.

Office 365 users who have Advanced Threat Protection in place, will be relieved to know that it does detect the spam emails, with malicious links, which try to introduce the malware to your system.  However, ATP does not come as standard with Office 365, it is optional additional service, which has a small per user fee.   We strongly recommend all of our IT Support customers have ATP in place.  It is a powerful tool which brings an additional layer of protection to your system.  We always recommend a layered approach to cyber security and ATP is a key element of this.

If you need advice on making sure your system is cyber- secure, contact us today, and one of our Technical Consultants will be in touch to help.

 RedMosquito provide IT Support and IT Security Services thoughout Glasgow, Edinburgh, Scotland and the UK. 

The Growing Importance of Cybersecurity for Irish SMEs in 2025

The Growing Importance of Cybersecurity for Irish SMEs in 2025

Introduction The digital world is evolving at an unprecedented pace, and with it, the risks that businesses face are also growing. Cybersecurity is no longer just a concern for large corporations; it has become a critical priority for Small and Medium Enterprises (SMEs) in Ireland. Many SMEs mistakenly believe that[…]

19 Mar 2025
The Future of IT Support: How Irish Businesses Can Stay Ahead in 2025

The Future of IT Support: How Irish Businesses Can Stay Ahead in 2025

Introduction The way businesses approach IT support is undergoing a significant transformation. In the past, IT support was primarily reactive—companies would only call for help when something broke. However, in 2025, Irish businesses must adopt a proactive approach, ensuring that systems remain efficient, secure, and[…]

18 Mar 2025
Disaster Recovery Planning: Why Irish Businesses Need It in 2025

Disaster Recovery Planning: Why Irish Businesses Need It in 2025

Introduction Unexpected IT failures, cyberattacks, and natural disasters pose serious risks to businesses. Without a solid disaster recovery plan (DRP), companies may suffer data loss, operational downtime, and financial damage.

17 Mar 2025
Cloud Computing Trends: How Irish Businesses Can Benefit in 2025

Cloud Computing Trends: How Irish Businesses Can Benefit in 2025

Introduction Cloud computing is no longer just an IT trend; it has become the foundation of modern business operations. Over the past decade, companies in Ireland have transitioned from traditional on-premise IT infrastructure to cloud-based solutions, benefiting from scalability, flexibility, and cost efficiency.

15 Mar 2025