JanelaRAT’s Evolving Multi-Stage Attacks Sharpen Focus on Latin American Banks

JanelaRAT operators have refined their multi-stage infection chains to increase precision and efficiency in targeting Latin American banking users. The malware’s custom title-bar detection ensures credential theft only activates on specific bank websites, maximizing the value of stolen data while reducing noise from irrelevant captures. Telemetry from 2025 shows over 14,700 attacks in Brazil and nearly 12,000 in Mexico, with additional activity in Chile and Colombia. The infection chain now includes MSI installers delivering DLL sideloading payloads, streamlining deployment and evading detection. This evolution reflects a deliberate effort to optimize infection success and persistence in financial services environments. The campaign’s continuous updates and regional focus indicate that JanelaRAT operators prioritize stealthy, high-value financial espionage. This targeted approach means that even partial mitigations may not prevent significant credential theft, as the malware activates only under precise conditions tied to victim browsing behavior.

Part of the PlainSec briefing for 2026-04-14

Sources