JanelaRAT malware continues to target Latin American banks

As reported by The Hacker News, banks and financial institutions in Latin American countries, particularly Brazil and Mexico, remain under persistent attack from a sophisticated malware family known as JanelaRAT. This threat, a modified version of BX RAT, is designed to steal sensitive financial and cryptocurrency data.JanelaRAT employs a custom title bar detection mechanism to identify and target specific financial websites. Its capabilities include logging keystrokes, capturing screenshots, and collecting system metadata. Initial infection vectors have evolved from ZIP archives containing VBScript to rogue MSI installer files, often distributed via platforms like GitLab.The malware utilizes DLL side-loading techniques for installation and establishes persistence through Windows Startup folders. It communicates with command-and-control servers to exfiltrate data, impersonates bank dialogs for credential harvesting, and monitors user activity to time malicious operations. Recent analyses indicate the malware can detect and evade anti-fraud systems and sandbox environments.Source:The Hacker News 

Latest articles

Related articles