• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
new financial malware 'janelarat' targets latin american users

New Financial Malware ‘JanelaRAT’ Targets Latin American Users

You are here: Home / General Cyber Security News / New Financial Malware ‘JanelaRAT’ Targets Latin American Users
August 14, 2023

End users in Latin America (LATAM) are the concentrate on of a fiscal malware known as JanelaRAT which is capable of capturing sensitive info from compromised Microsoft Windows programs.

“JanelaRAT primarily targets financial and cryptocurrency facts from LATAM financial institution and money institutions,” Zscaler ThreatLabz researchers Gaetano Pellegrino and Sudeep Singh reported, including it “abuses DLL aspect-loading techniques from authentic resources (like VMWare and Microsoft) to evade endpoint detection.”

The precise starting up position of the infection chain is unclear, but the cybersecurity corporation, which uncovered the marketing campaign in June 2023, claimed the unfamiliar vector is employed to deliver a ZIP archive file that contains a Visual Basic Script.

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


Cybersecurity

The VBScript is engineered to fetch a next ZIP archive from the attackers’ server as properly as fall a batch file used to create persistence of the malware.

The ZIP archive is packed with two components, the JanelaRAT payload and a legitimate executable — identification_helper.exe or vmnat.exe — that is utilized to launch the former by usually means of DLL facet-loading.

JanelaRAT, for its aspect, employs string encryption and transitions into an idle condition when required to stay away from evaluation and detection. It can be also a intensely modified variant of BX RAT, which was first found out in 2014.

A single of the new additions to the trojan is its potential to capture windows titles and ship them to the threat actors, but not right before registering the newly-contaminated host with the command-and-handle (C2) server. Other options of JanelaRAT let it to keep track of mouse inputs, log keystrokes, take screenshots, and harvest procedure metadata.

“JanelaRAT ships with just a subset of the functions made available by BX RAT,” the researchers mentioned. “The JanelaRAT developer failed to import shell commands execution features, or data files and procedures manipulation functionalities.”

Cybersecurity

A closer investigation of the source code has exposed the existence of many strings in Portuguese, indicating that the creator is acquainted with the language.

The inbound links to LATAM arrive from references to companies functioning in the banking and decentralized finance verticals and the simple fact that the VBScript uploads to VirusTotal originated from Chile, Colombia, and Mexico.

“The use of first or modified commodity Distant Accessibility Trojans (RATs) is popular among danger actors working in the LATAM region,” the scientists explained. “JanelaRAT’s concentration on harvesting LATAM fiscal details and its approach of extracting window titles for transmission underscores its specific and stealthy character.”

Observed this short article fascinating? Comply with us on Twitter  and LinkedIn to go through far more distinctive content material we article.


Some pieces of this article are sourced from:
thehackernews.com

Previous Post: «india passes new digital personal data protection bill (dpdpb), putting India Passes New Digital Personal Data Protection Bill (DPDPB), Putting Users’ Privacy First
Next Post: Charming Kitten Targets Iranian Dissidents with Advanced Cyber Attacks charming kitten targets iranian dissidents with advanced cyber attacks»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.