Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
Their developers often distribute samples via phishing emails, sometimes casting a wide net and other times targeting specific individuals. These emails often masquerade as official correspondence related to tax or compliance matters, and occasionally attempt to impersonate government or tax agencies themselves.
The attacker, in real time, receives screen captures, the logged keystrokes and information that is entered in the fake forms.
These pop-ups contain fake forms, aiming to trick the malware’s victims into entering their banking credentials and personal information that the malware captures and exfiltrates to its C&C servers.
Janeleiro begins enumerating windows and checking their titles to find interesting keywords... that would indicate that the user is visiting the website of a banking entity of interest.
The attacker, in real time, receives screen captures, the logged keystrokes and information that is entered in the fake forms.
These pop-ups contain fake forms, aiming to trick the malware’s victims into entering their banking credentials and personal information that the malware captures and exfiltrates to its C&C servers.
33 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a known banking trojan family in the Latin American banking trojan ecosystem.
Latin American banking trojan written in .NET, mentioned as a newer discovery and possible sign of continued evolution in this malware ecosystem.
Brazil-focused banking trojan targeting corporate users via phishing emails and MSI/ZIP delivery. It monitors window titles for banking-related keywords, displays attacker-controlled fake banking pop-up windows, captures credentials and personal data, performs keylogging and screen capture, exfiltrates data to C2, and in some versions also deploys a password-stealing module and clipboard hijacking for bitcoin addresses. It uses GitHub repositories/organization pages as dead-drop resolvers for C2 server lists and includes geolocation checks to restrict execution to Brazil.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.