ThreatLabz
ID: 19d0ae82-e388-51fe-8fec-7a9f9fb21206
STIX ID: report--19d0ae82-e388-51fe-8fec-7a9f9fb21206
Feed Name: Zscaler Security Research Blog
JanelaRAT is a Windows remote-access trojan analyzed in this report that actively monitors foreground window titles (using a downloadable kepler186f.txt list) to detect financially-relevant applications, captures screenshots, logs mouse and keyboard activity, supports remote desktop sessions, can block or close specified windows via block.blq, display fake modal dialogs to deceive users, and execute a range of attacker-controlled actions and modes; the sample examined was active at the time of analysis and includes explicit artifacts and behaviors enabling credential/data theft and persistent remote control.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
