JanelaRAT Uses Fake Windows Updates to Empty LATAM Bank Accounts
ID: 9e2bc977-6079-5bb3-bbf8-37cf2826e2b5
STIX ID: report--9e2bc977-6079-5bb3-bbf8-37cf2826e2b5
Feed Name: securityonline.info
Threat Score
JanelaRAT is a sophisticated banking-focused Remote Access Trojan active in Latin America that uses deceptive invoice emails, malicious downloads (ZIP/MSI), DLL sideloading, and a custom title-bar detection to monitor and hijack live banking sessions; it employs inactivity tracking and full-screen decoy overlays to capture credentials and bypass MFA, with Kaspersky telemetry reporting 14,739 attacks in Brazil and 11,695 in Mexico in 2025.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
