logo

JanelaRAT Malware Targets Latin American Banks with 14,739 Attacks in Brazil in 2025

ID: 2c41a618-6550-5ed6-8222-17981b8e6dde

STIX ID: report--2c41a618-6550-5ed6-8222-17981b8e6dde

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-04-13

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

JanelaRAT is an actively deployed remote access trojan targeting banks and financial institutions across Latin America (notably Brazil, Mexico, Chile, and Colombia). Operators deliver the malware via phishing links to ZIP archives or rogue MSI installers that use DLL side-loading and orchestrating scripts to install a RAT, browser extensions, and supporting components; once installed it establishes C2 communications, persists via Startup LNKs, and performs credential theft, screenshots, input injection, fake overlays, keystroke capture, and anti-analysis checks to intercept financial interactions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.