Janela RAT Spreads via Fake MSI Installers, Malicious Extensions
ID: 2001560f-26b5-5a63-9614-aaec1fe33503
STIX ID: report--2001560f-26b5-5a63-9614-aaec1fe33503
Feed Name: GBHackers
Janela RAT, a modified variant of BX RAT, is being distributed through public GitLab-hosted fake MSI installers targeting users in Chile, Colombia, and Mexico; infections use Go/PowerShell/batch unpackers to deploy a password-protected payload that includes the RAT executable and a malicious Chromium extension which registers a native messaging host to harvest browser data (history, cookies, extensions, tab activity) and automatically collect credentials for banking and cryptocurrency sites, while communicating with encrypted WebSocket C2 servers and using obfuscation and idle-state evasion to persist and avoid detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
