JanelaRAT is a Windows-based banking trojan and remote access malware family active since at least June 2023 and derived from BX RAT. It is tailored for financial fraud against banks, financial institutions, and cryptocurrency-related targets in Latin America, with Brazil and Mexico repeatedly identified as major focus countries. The malware’s name reflects its core tradecraft: monitoring active window titles to detect when a victim is interacting with targeted banking or financial services, then triggering operator-driven actions during those sessions.
JanelaRAT profiles infected hosts, gathers system metadata, tracks user activity and inactivity, captures screenshots, logs keystrokes, records mouse activity, and communicates with command-and-control infrastructure over socket-based channels. It compares foreground window titles against attacker-supplied or embedded lists of targeted institutions and financial terms, and when a match is found it can open a dedicated channel for alerting operators and transmitting surveillance data. Observed functionality also includes displaying attacker-controlled message boxes, simulating keyboard and mouse input, executing commands, manipulating the user interface, shutting down or suspending the host, and removing monitoring hooks.
A notable feature is its use of deceptive overlays and fake dialogs to facilitate banking fraud. JanelaRAT can close selected windows, present counterfeit error messages, display bank-themed prompts, and show fake update or loading screens intended to suppress user interaction while harvesting credentials or other sensitive financial information. Some reporting also attributes session-focused fraud capabilities to newer variants, including interception of live banking activity rather than simple credential collection alone. Anti-analysis and anti-fraud-awareness features have also been observed, including sandbox-evasion checks and logic intended to detect banking security tooling.
Delivery and installation chains have evolved over time. Earlier campaigns used phishing lures and compressed archives containing script-based downloaders, while later activity shifted toward rogue MSI installers masquerading as legitimate software. Installation commonly relies on DLL side-loading of the final payload and persistence through Windows Startup-folder shortcuts or scripts. Operators have also been observed refining the malware and its infection chain over time, including use of obfuscation and encrypted strings to hinder analysis.
JanelaRAT is associated with financially motivated cybercrime rather than espionage and is best characterized as a Latin America-focused banking trojan with RAT-like interactive control features. Its operational emphasis is theft of banking and cryptocurrency-related data, credential harvesting, and real-time monitoring of victim financial sessions.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
35 distinct techniques documented for this family, organized by ATT&CK tactic.
Mode 1 Shuts down the infected system by issuing the shutdown shell command.
Upon execution, the installer initiates a multi-stage infection process using orchestrating scripts written in Go, PowerShell, and batch...
Some of the supported commands include ... Running commands using "cmd.exe" and PowerShell commands or scripts
First detected in the wild by Zscaler in June 2023, JanelaRAT has leveraged ZIP archives containing a Visual Basic Script (VBScript) to download a second ZIP file...
cmd /min /C REG ADD HKCUControl PanelDesktop /v Win8DpiScaling /t REG_DWORD /d 0x00000001 /f
These scripts unpack a ZIP archive containing the RAT executable, a malicious Chromium-based browser extension, and supporting components.
The content is encrypted with the same algorithm used for the strings.
...distributed via rogue MSI installer files masquerading as legitimate software hosted on trusted platforms like GitLab.
Mode 10 Deletes the file block.blq if it exists in the same folder as JanelaRAT.
Recent analyses indicate the malware can detect and evade anti-fraud systems and sandbox environments.
Some of the supported commands include ... Simulating keyboard actions like DOWN, UP, and TAB for navigation Moving the cursor and simulating clicks | ...displaying images in full-screen mode ... and impersonating bank-themed dialogs via fake overlays to harvest credentials
This channel is later used for alerting the threat attacker about the victim opening interesting windows, sending key logs, mouse clicks, and implementing remote desktop sessions.
JanelaRAT captures the content of windows title bars and checks if they are interesting for the threat attacker.
System usage information gathered by JanelaRAT Index Element 0 User 1 [username of the user currently logged in]
7 [comma-separated list of IP addresses currently associated with the infected system]
JanelaRAT is capable of collecting and sending information about the compromised host to the attacker.
The browser add-on then proceeds to gather system information, cookies, browsing history, installed extensions, and tab metadata...
Some of the supported commands include ... Simulating keyboard actions like DOWN, UP, and TAB for navigation Moving the cursor and simulating clicks | ...displaying images in full-screen mode ... and impersonating bank-themed dialogs via fake overlays to harvest credentials
This channel is later used for alerting the threat attacker about the victim opening interesting windows, sending key logs, mouse clicks, and implementing remote desktop sessions.
It communicates with command-and-control servers to exfiltrate data, impersonates bank dialogs for credential harvesting, and monitors user activity to time malicious operations.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware family targeting financial and cryptocurrency data from selected banks and institutions in Latin America. It is described as a modified version of BX RAT and uses a custom title bar detection method to identify specific websites in a victim’s browser.
A modified BX RAT variant targeting financial institutions, designed to steal financial and cryptocurrency data. It uses title bar detection to target financial websites, logs keystrokes, captures screenshots, collects system metadata, uses DLL side-loading for installation, persists via Windows Startup folders, communicates with C2 servers for data exfiltration, impersonates bank dialogs for credential harvesting, and can evade anti-fraud systems and sandbox environments.
A remote access trojan targeting financial institutions and users in Latin America. It steals financial and cryptocurrency data, monitors user activity, captures screenshots and keystrokes, communicates with C2 servers, deploys fake overlays to harvest credentials, manipulates browser behavior via a malicious extension, and supports remote control actions such as command execution, cursor movement, and shutdown.
A Latin America-focused banking malware/RAT that targets financial and cryptocurrency users, especially in Brazil and Mexico. It monitors active banking sessions via window-title matching, communicates with C2 over TCP/HTTP, supports screenshots, keylogging, command execution, input simulation, overlays for credential and MFA theft, persistence, anti-analysis checks, and live banking session hijacking.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.