Javali is a Brazilian banking Trojan associated with the Latin American banking malware ecosystem and grouped with Guildma, Melcoz, and Grandoreiro in the cluster often referred to as the Tétrade. It has been observed expanding beyond South America into other regions, including Europe, as part of the broader internationalization of Brazilian financial malware operations.
Javali targets Windows systems and focuses on credential theft from web browsers and banking workflows. Documented behavior includes monitoring running processes for open browsers and custom banking applications, as well as capturing login credentials from browsers such as Firefox, Chrome, Internet Explorer, and Edge. Its use of process monitoring indicates victim-environment awareness oriented toward identifying active banking sessions and suitable targets for theft.
Execution and delivery have relied on phishing emails, including both malicious attachments and malicious links embedded in email messages. Reported attachment-based infection chains include MSI installers containing embedded VBScript, with the script used to download additional malicious payloads. Javali has also used MSI-based execution to retrieve and run follow-on components.
For defense evasion and execution, Javali has employed DLL side-loading to load malicious libraries through legitimate executables. This tradecraft aligns with broader patterns seen in banking malware seeking to blend into normal application behavior while reducing detection.
Javali is best characterized as a banking Trojan with credential-stealing functionality, delivered primarily through email-based social engineering and designed to compromise online banking activity on Windows endpoints.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes threat actors and malware being delivered through phishing or spearphishing emails containing malicious attachments such as Microsoft Office documents, PDFs, RAR/ZIP archives, CHM, ISO, IMG, HTA, LNK, and executable files disguised as documents.
Multiple actors and malware families are described as being delivered via spearphishing/phishing emails containing malicious links (e.g., APT28 used URL shorteners to redirect to credential harvesting sites; APT29 used links to ZIP files; APT33 used links to .hta files; BlackTech used links to cloud services; Wizard Spider used links to Google Drive/free file hosting).
APT-C-36 has embedded a VBScript within a malicious Word document which is executed upon the document opening.
In the first scenario, the JavaScript is executed via CustomAction. The JavaScript code is obfuscated, likely in an attempt to slow down analysis.
has attempted to get victims to launch malicious Microsoft Word attachments delivered via spearphishing emails... has required user execution of a malicious MSI installer... has been executed through user installation of an executable disguised as a flash installer.
The JavaScript code is obfuscated, likely in an attempt to slow down analysis... Aside from decrypting the payload, the second stage also decrypts the code that will execute Ousaban in runtime, probably to slow down reverse engineering... Ousaban commonly packs/protects its payloads with UPX or Enigma.
A script downloads an image that looks like a PDF icon but hides a ZIP file inside, a trick called steganography.
Important API calls used by this stage are also dynamically resolved, another common technique to slow down reverse engineering.
The script unpacks Ousaban from that ZIP, runs it, then deletes the image, the ZIP, and itself to leave less behind.
“avisoProtesto.exe” is a signed and non-malicious binary exploited to execute the malicious DLL via DLL search order hijacking.
When a target bank loads, it can capture screenshots and keystrokes, tamper with the clipboard, show fake messages, and give the attacker remote control.
Agent Tesla can gather credentials from a number of browsers... APT33 has used a variety of publicly available tools like LaZagne to gather credentials... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge... SELECT action_url, username_value, password_value FROM logins; CryptUnprotectData
Agent Tesla can gather credentials from a number of browsers... APT3 has used tools to dump passwords from browsers... APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge
Like other Brazilian-sourced malware, Ousaban monitors the title text from the active window and compares it with a list of strings, to verify if the victim is accessing the website or an application of one of its targets.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
When a target bank loads, it can capture screenshots and keystrokes, tamper with the clipboard, show fake messages, and give the attacker remote control.
When a target bank loads, it can capture screenshots and keystrokes, tamper with the clipboard, show fake messages, and give the attacker remote control.
the threat often abuses cloud services, such as Amazon S3 to download second stage payloads, and Google Docs to retrieve the C2 configuration... the malware is using Pastebin to fetch the data... contain a routine to communicate via Telegram using Webhooks
The content repeatedly describes malware and threat actors that can "download files from C2," "download additional payloads," "upload and download files," "retrieve payloads from the C2 server," and "copy files to remote machines."
30 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Uses embedded VBScript to download malicious payloads from command-and-control servers.
Malware executed through malicious attachments including MSI files with embedded VBScript.
Banking trojan capable of capturing login credentials from open browsers.
Banking trojan that monitors processes for browsers and banking applications.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.