The Astaroth Trojan was first spotted by security firm Cofense in late 2018 when it was involved in a campaign targeting Europe and Brazil. The malware abused living-off-the-land binaries (LOLbins) such as the command line interface of the Windows Management Instrumentation Console (WMIC) to download and install malicious payloads in the background. Malware is able to log the users keystrokes, collect information through hooking, access clipboard content, and monitor the keystate.”]
Source: https://securityaffairs.co/wordpress/88115/malware/astaroth-trojan-campaign-fileless.html

