Brazilian Banks Targeted by New AllaKore RAT Variant Called AllaSenha
ID: b3720e84-a775-50ec-b9fd-16ea6bf9e868
STIX ID: report--b3720e84-a775-50ec-b9fd-16ea6bf9e868
Feed Name: The Hacker News
A new Brazil-focused banking malware campaign distributes a custom AllaKore-derived RAT called AllaSenha that steals browser-stored banking credentials and intercepts 2FA via overlay windows and QR social-engineering. Initial access appears to come from phishing using a malicious LNK that launches a PowerShell/Base64 chain to download a Python-based loader (BPyCode) which retrieves a DLL via DGA/Azure-hosted infrastructure and performs in-memory DLL injection to execute the banker; Cisco Talos linked the activity to Brazilian operators tracked as CarnavalHeist. The report also notes Android dropper apps on Google Play delivering the Anatsa banking trojan and broader actor reuse of cloud and code-hosting services to stage payloads.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
