logo

JanelaRAT: a financial threat targeting users in Latin America

ID: fc4cb3d2-a32a-522b-b07e-166c70f9dc02

STIX ID: report--fc4cb3d2-a32a-522b-b07e-166c70f9dc02

Feed Name: Securelist by Kaspersky

Threat Score
80/100

Date Published: 2026-04-13

Date Updated: 2026-04-29

Author: GReAT

...
...

JanelaRAT is an actively evolving banking-targeted RAT used in large malspam campaigns against Latin American users (notably Brazil and Mexico); it uses MSI droppers and DLL sideloading to persist and execute a .NET backdoor that performs real-time session hijacking via full-screen overlays, input injection, keylogging, screenshot exfiltration, and dynamic (date-rotating) C2 channels with anti-analysis and obfuscation techniques—telemetry shows thousands of infections and the report includes technical behavior, persistence details, mitigation advice (block DDNS), and IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.