logo

Inside agenteV2: How Brazilian Attackers Use Fake Court Summons to Steal Banking Credentials in Real Time 

ID: fc026219-21ab-5f29-80f3-225db654e165

STIX ID: report--fc026219-21ab-5f29-80f3-225db654e165

Feed Name: ANY.RUN's Cybersecurity Blog

Threat Score
85/100

Date Published: 2026-04-24

Date Updated: 2026-04-26

Author: Moises Cerqueira (0xOlympus)

...
...

This report analyzes the agenteV2 campaign: a Brazilian-focused phishing operation delivering a VBS loader that installs a Nuitka-compiled stealer DLL which establishes a persistent WebSocket backdoor (uws://) to stream the victim's screen and provide an interactive remote shell for operator-assisted banking fraud; the analysis provides full infection-chain details, IOCs (domains, IPs, hashes, JA3), MITRE mapping, and remediation/detection recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.