The Cyber Security Authority (CSA) in Ghana has issued a public alert, warning Windows computer users about a new and dangerous malware campaign. The attack, which leverages the popular messaging platform WhatsApp Web, involves a banking malware known as Astaroth, posing a significant threat to both individuals and organisations across the country.

According to the CSA's alert, the modus operandi of the attackers involves sending malicious ZIP files through WhatsApp messages. These files are often cleverly disguised as legitimate documents, enticing unsuspecting users to download and open them. Once a user downloads and opens such a file on a Windows-based device, the Astaroth malware installs itself silently in the background, without any notification or consent from the user.

Upon successful installation, the malware immediately connects to the victim's WhatsApp Web session. It then proceeds to retrieve the user's contact list and automatically sends similar malicious files to these contacts. This automated propagation mechanism allows the malware to spread rapidly across networks, compromising multiple users while simultaneously harvesting sensitive data from infected machines.

The CSA has highlighted the severe capabilities of the Astaroth malware, warning that it can steal critical personal and financial information. This includes banking login details, one-time passwords (OTPs), browser cookies, and even keystrokes, which could compromise virtually all online activities. In light of these threats, the authority has urged the public to exercise extreme caution.

Users are strongly advised to avoid opening unexpected files, even if they appear to come from known contacts. Furthermore, the CSA recommends regularly checking active WhatsApp Web sessions for any unfamiliar connections, keeping operating systems and applications updated to patch known vulnerabilities, and utilising reliable security software to detect and prevent malware infections.