Researchers reported that JanelaRAT, a Latin America-focused banking trojan derived from BX RAT, is actively targeting online banking and cryptocurrency users, with the heaviest activity in Brazil and Mexico and additional campaigns observed in Chile and Colombia. Kaspersky said it recorded 14,739 detections in Brazil and 11,695 in Mexico during 2025, as the malware continued to evolve from earlier VBScript-and-ZIP delivery chains to newer phishing-led infections using MSI droppers, DLL sideloading, obfuscated .NET payloads, and persistence through Startup-folder LNK files. Recent activity also included deployment of a malicious Chromium extension disguised as legitimate software.
Once installed, JanelaRAT monitors browser and window titles for hard-coded banking and financial targets, then opens interactive TCP and HTTP command-and-control channels to support screenshots, keylogging, input injection, cursor control, remote command execution, and session hijacking. The malware uses encrypted strings, anti-analysis checks, daily rotating dynamic DNS infrastructure, and user inactivity monitoring to evade detection and help operators time fraudulent transactions. A notable feature is its overlay system, which displays fake banking prompts and Windows update screens to steal credentials and MFA tokens while suppressing user interaction.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Kaspersky detailed JanelaRAT's current functionality, including banking-session monitoring via browser window titles, interactive C2 communications, overlays for credential and MFA theft, keylogging, screenshots, and anti-analysis checks. The report also described dynamic DNS-based infrastructure and decoy banking and Windows update screens used to facilitate fraud.
Researchers reported that newer JanelaRAT campaigns shifted from an earlier VBScript-and-ZIP delivery method to an MSI-based installer chain using DLL side-loading, Startup-folder persistence, and in some cases a malicious Chromium extension. This reflected an evolution in the malware's delivery and persistence techniques.
Throughout 2025, Kaspersky recorded substantial JanelaRAT activity aimed at financial users, including 14,739 detections in Brazil and 11,695 in Mexico. The campaigns targeted online banking and cryptocurrency users with phishing-led infection chains.
The new reference states JanelaRAT has been active since June 2023 and describes it as a modified version of BX RAT targeting financial and cryptocurrency data in Latin America. It also notes the malware uses custom browser title-bar detection to identify targeted banking and institutional websites.
KPMG previously documented JanelaRAT activity targeting users in Chile, Colombia, and Mexico, indicating the banking trojan's expansion beyond a single country in Latin America. The reference does not provide a specific date for these observations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
community.gurucul.com
Open sourcescworld.com
Open sourcecybersecuritynews.com
Open sourcethehackernews.com
Open sourcesecurelist.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.