Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
JanelaRAT Malware Hits Latin American Banks Hard

JanelaRAT Malware Hits Latin American Banks Hard

Posted on April 13, 2026 By CWS

The JanelaRAT malware has been aggressively targeting financial institutions across Latin America, specifically in countries such as Brazil and Mexico. This malicious software, a variant of the BX RAT, is designed to pilfer sensitive financial and cryptocurrency data from specific organizations. Additionally, it records keystrokes, monitors mouse activities, captures screenshots, and collects significant system information.

JanelaRAT’s Unique Mechanism

One noteworthy aspect of JanelaRAT is its use of a specialized title bar detection method to identify targeted websites in users’ browsers, enabling it to execute harmful activities. According to a recent Kaspersky report, the cybercriminals behind these operations are continually enhancing the malware’s infection pathways and capabilities by integrating new functionalities.

Data from Kaspersky indicates a staggering 14,739 attack attempts in Brazil throughout 2025, alongside 11,695 in Mexico. The exact number of successful breaches remains uncertain. Initially identified by Zscaler in June 2023, JanelaRAT employs ZIP archives containing VBScript to download another ZIP file with a legitimate executable and a DLL payload, ultimately executing the trojan through DLL side-loading.

Distribution and Attack Tactics

Subsequent analysis by KPMG in July 2025 revealed that JanelaRAT is distributed via misleading MSI installer files, posing as genuine software on reputable platforms like GitLab. These attacks primarily target regions such as Chile, Colombia, and Mexico. The MSI installers initiate a complex infection process using scripts written in languages like Go and PowerShell, which unpack a ZIP archive containing the RAT executable and a malicious browser extension.

The operation involves the scripts identifying installed Chromium-based browsers and modifying their launch settings to install the extension stealthily. This add-on accumulates system data, browsing history, and more, while executing specific tasks based on URL patterns.

Advanced Attack Strategies

Recent Kaspersky findings highlight phishing emails disguised as invoices that lure victims into downloading a PDF, triggering a download of a ZIP file that initiates the attack chain. Since May 2024, JanelaRAT has transitioned from using VBScript to MSI installers, which employ DLL side-loading to establish persistence by creating a startup folder shortcut.

Upon activation, the malware connects to a command-and-control (C2) server to track the victim’s activities and intercept sensitive financial interactions. It monitors active windows to identify financial institutions listed in its code. If a match is found, it opens a dedicated C2 channel to execute malicious tasks. These tasks range from capturing screenshots to executing system commands and simulating user interactions.

Kaspersky notes that the malware can detect inactivity on the victim’s machine and notify the C2 server after 10 minutes of inactivity, resuming its operations upon detecting user activity. This version of JanelaRAT signifies a major leap in the attackers’ capabilities, featuring multiple communication channels, extensive monitoring, and sophisticated remote control mechanisms, all while evading detection by anti-fraud systems.

The Hacker News Tags:Banks, Brazil, BX RAT, Cybersecurity, DLL side-loading, JanelaRAT, Kaspersky, Latin America, Malware, Mexico, MSI installers, Phishing

Post navigation

Previous Post: Critical Marimo Flaw Exploited Within Hours of Disclosure
Next Post: Critical Axios Flaw Risks Cloud Security Breach

Related Posts

Zero-Day Exploits, Developer Malware, IoT Botnets, and AI-Powered Scams Zero-Day Exploits, Developer Malware, IoT Botnets, and AI-Powered Scams The Hacker News
N. Korean Hackers Used Job Lures, Cloud Account Access, and Malware to Steal Millions in Crypto N. Korean Hackers Used Job Lures, Cloud Account Access, and Malware to Steal Millions in Crypto The Hacker News
Scattered Spider Hacker Gets 10 Years, M Restitution for SIM Swapping Crypto Theft Scattered Spider Hacker Gets 10 Years, $13M Restitution for SIM Swapping Crypto Theft The Hacker News
Water Curse Employs 76 GitHub Accounts to Deliver Multi-Stage Malware Campaign Water Curse Employs 76 GitHub Accounts to Deliver Multi-Stage Malware Campaign The Hacker News
67 Trojanized GitHub Repositories Found in Campaign Targeting Gamers and Developers 67 Trojanized GitHub Repositories Found in Campaign Targeting Gamers and Developers The Hacker News
Evelyn Stealer Malware Abuses VS Code Extensions to Steal Developer Credentials and Crypto Evelyn Stealer Malware Abuses VS Code Extensions to Steal Developer Credentials and Crypto The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Axios Flaw Risks Cloud Security Breach
  • JanelaRAT Malware Hits Latin American Banks Hard
  • Critical Marimo Flaw Exploited Within Hours of Disclosure
  • Phishing Attacks Exploit GitHub and Jira Notifications
  • Nginx 1.29.8 & FreeNginx Update Bolster Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Axios Flaw Risks Cloud Security Breach
  • JanelaRAT Malware Hits Latin American Banks Hard
  • Critical Marimo Flaw Exploited Within Hours of Disclosure
  • Phishing Attacks Exploit GitHub and Jira Notifications
  • Nginx 1.29.8 & FreeNginx Update Bolster Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark