logo

JanelaRAT Uses Fake Windows Updates to Empty LATAM Bank Accounts

ID: 9e2bc977-6079-5bb3-bbf8-37cf2826e2b5

STIX ID: report--9e2bc977-6079-5bb3-bbf8-37cf2826e2b5

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-04-15

Date Updated: 2026-04-23

Author: Ddos

...
...

JanelaRAT is a sophisticated banking-focused Remote Access Trojan active in Latin America that uses deceptive invoice emails, malicious downloads (ZIP/MSI), DLL sideloading, and a custom title-bar detection to monitor and hijack live banking sessions; it employs inactivity tracking and full-screen decoy overlays to capture credentials and bypass MFA, with Kaspersky telemetry reporting 14,739 attacks in Brazil and 11,695 in Mexico in 2025.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.