Rust-Based VENON Malware Targets 33 Brazilian Banks with Credential-Stealing Overlays
ID: 5c4fd052-2fb1-5eb9-9690-04d0c442ee54
STIX ID: report--5c4fd052-2fb1-5eb9-9690-04d0c442ee54
Feed Name: The Hacker News
Researchers disclosed VENON, a Rust-written banking trojan targeting Brazilian Windows users that departs from regional Delphi-based families; it uses DLL side-loading, nine evasion techniques (anti-sandbox checks, indirect syscalls, ETW and AMSI bypass), retrieves configuration from Google Cloud Storage, installs scheduled tasks, maintains WebSocket C2 communications, and implements LNK shortcut hijacking and fake overlays to steal credentials from 33 financial institutions. The report also links VENON’s distribution to social-engineering lures and a PowerShell-delivered ZIP, and situates the threat amid WhatsApp-based SORVEPOTEL campaigns that have delivered other banking malware.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
