Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
financial-sector-threatcredential-stealer-activityremote-access-implantphishing-campaign-intelligence

JanelaRAT Banking Trojan Expands Attacks on Latin American Financial Users

Updated 2mo agoFirst seen Apr 13, 20265 sources

Researchers reported that JanelaRAT, a Latin America-focused banking trojan derived from BX RAT, is actively targeting online banking and cryptocurrency users, with the heaviest activity in Brazil and Mexico and additional campaigns observed in Chile and Colombia. Kaspersky said it recorded 14,739 detections in Brazil and 11,695 in Mexico during 2025, as the malware continued to evolve from earlier VBScript-and-ZIP delivery chains to newer phishing-led infections using MSI droppers, DLL sideloading, obfuscated .NET payloads, and persistence through Startup-folder LNK files. Recent activity also included deployment of a malicious Chromium extension disguised as legitimate software.

Once installed, JanelaRAT monitors browser and window titles for hard-coded banking and financial targets, then opens interactive TCP and HTTP command-and-control channels to support screenshots, keylogging, input injection, cursor control, remote command execution, and session hijacking. The malware uses encrypted strings, anti-analysis checks, daily rotating dynamic DNS infrastructure, and user inactivity monitoring to evade detection and help operators time fraudulent transactions. A notable feature is its overlay system, which displays fake banking prompts and Windows update screens to steal credentials and MFA tokens while suppressing user interaction.

Share:
JanelaRAT Banking Trojan Expands Attacks on Latin American Financial Users
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Mar 10, 20264mo ago

Kaspersky publishes technical analysis of JanelaRAT's latest capabilities

Kaspersky detailed JanelaRAT's current functionality, including banking-session monitoring via browser window titles, interactive C2 communications, overlays for credential and MFA theft, keylogging, screenshots, and anti-analysis checks. The report also described dynamic DNS-based infrastructure and decoy banking and Windows update screens used to facilitate fraud.

Researchers identify newer MSI-based JanelaRAT infection chain

Researchers reported that newer JanelaRAT campaigns shifted from an earlier VBScript-and-ZIP delivery method to an MSI-based installer chain using DLL side-loading, Startup-folder persistence, and in some cases a malicious Chromium extension. This reflected an evolution in the malware's delivery and persistence techniques.

Jan 1, 20251y ago

JanelaRAT conducts heavy banking malware activity in Brazil and Mexico during 2025

Throughout 2025, Kaspersky recorded substantial JanelaRAT activity aimed at financial users, including 14,739 detections in Brazil and 11,695 in Mexico. The campaigns targeted online banking and cryptocurrency users with phishing-led infection chains.

Jun 1, 20233y ago

JanelaRAT activity begins as a modified BX RAT malware family

The new reference states JanelaRAT has been active since June 2023 and describes it as a modified version of BX RAT targeting financial and cryptocurrency data in Latin America. It also notes the malware uses custom browser title-bar detection to identify targeted banking and institutional websites.

JanelaRAT: A Financial Threat Targeting Users in Latin America | Community Portal | Gurucul

KPMG observes JanelaRAT campaigns in Chile, Colombia, and Mexico

KPMG previously documented JanelaRAT activity targeting users in Chile, Colombia, and Mexico, indicating the banking trojan's expansion beyond a single country in Latin America. The reference does not provide a specific date for these observations.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

10 LINKEDOpen in app
Affected products
2 linked
PowershellGitlab
Organizations
5 linked
GuruculGitLabKPMGKasperskyZscaler
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.