logo

Rust-Based VENON Malware Targets 33 Brazilian Banks with Credential-Stealing Overlays

ID: 5c4fd052-2fb1-5eb9-9690-04d0c442ee54

STIX ID: report--5c4fd052-2fb1-5eb9-9690-04d0c442ee54

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-03-12

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Researchers disclosed VENON, a Rust-written banking trojan targeting Brazilian Windows users that departs from regional Delphi-based families; it uses DLL side-loading, nine evasion techniques (anti-sandbox checks, indirect syscalls, ETW and AMSI bypass), retrieves configuration from Google Cloud Storage, installs scheduled tasks, maintains WebSocket C2 communications, and implements LNK shortcut hijacking and fake overlays to steal credentials from 33 financial institutions. The report also links VENON’s distribution to social-engineering lures and a PowerShell-delivered ZIP, and situates the threat amid WhatsApp-based SORVEPOTEL campaigns that have delivered other banking malware.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.