logo

New Janela Campaign Deploys Deceptive MSI Files, Malicious Extensions For Stealthy Theft

ID: d55f9b2c-e60f-587e-817d-409a1821e80c

STIX ID: report--d55f9b2c-e60f-587e-817d-409a1821e80c

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2026-04-14

Date Updated: 2026-04-14

Author: Varshini

...
...

**Executive summary:** A financially motivated campaign using Janela RAT has been observed targeting banking, fintech and cryptocurrency users in Chile, Colombia and Mexico via malicious MSI installers hosted on GitLab and a malicious Chromium extension that establishes native messaging for credential and data theft; the report details the multi-stage unpacking, password-protected ZIP handling, base64-encoded rotating C2 domains, persistence techniques, and provides domains, IPs and sample file hashes with attribution to a KPMG alert.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.