Threats · 154 days ago
JanelaRAT operators have refined their multi-stage infection chains to increase precision and efficiency in targeting Latin American banking users. The malware’s custom title-bar detection ensures credential theft only activates on specific bank websites, maximizing the value of stolen data while reducing noise from irrelevant captures.
Telemetry from 2025 shows over 14,700 attacks in Brazil and nearly 12,000 in Mexico, with additional activity in Chile and Colombia. The infection chain now includes MSI installers delivering DLL sideloading payloads, streamlining deployment and evading detection. This evolution reflects a deliberate effort to optimize infection success and persistence in financial services environments.
The campaign’s continuous updates and regional focus indicate that JanelaRAT operators prioritize stealthy, high-value financial espionage. This targeted approach means that even partial mitigations may not prevent significant credential theft, as the malware activates only under precise conditions tied to victim browsing behavior.
2 sources covering this story
JanelaRAT Malware Targets Latin American Banks with 14,739 Attacks in Brazil in 2025
JanelaRAT hits Latin American banks with 14,739 attacks in Brazil in 2025, enabling credential theft and financial espionage
JanelaRAT targeting online banking users in Latin America
Kaspersky GReAT experts describe the latest JanelaRAT campaign detailing infection chain and malware functionality updates.
Part of the PlainSec briefing for 2026-04-14