logo

Janela RAT Spreads via Fake MSI Installers, Malicious Extensions

ID: 2001560f-26b5-5a63-9614-aaec1fe33503

STIX ID: report--2001560f-26b5-5a63-9614-aaec1fe33503

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-04-14

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Janela RAT, a modified variant of BX RAT, is being distributed through public GitLab-hosted fake MSI installers targeting users in Chile, Colombia, and Mexico; infections use Go/PowerShell/batch unpackers to deploy a password-protected payload that includes the RAT executable and a malicious Chromium extension which registers a native messaging host to harvest browser data (history, cookies, extensions, tab activity) and automatically collect credentials for banking and cryptocurrency sites, while communicating with encrypted WebSocket C2 servers and using obfuscation and idle-state evasion to persist and avoid detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.