Back to Intel

Intel Node

JanelaRAT: a financial threat targeting users in Latin America

lowtradecraft2026-04-13T09:00:23+00:00source excerpt
malwaretradecraftdetectionemail

Source excerpt · The upstream feed supplied only part of this article.Read the original source →

Kaspersky GReAT experts describe the latest JanelaRAT campaign detailing infection chain and malware functionality updates.

Background JanelaRAT is a malware family that takes its name from the Portuguese word “janela” which means “window”. JanelaRAT looks for financial and cryptocurrency data from specific banks and financial institutions in the Latin America region. JanelaRAT is a modified variant of BX RAT that has targeted users since June 2023. One of the key differences between these Trojans is that JanelaRAT uses a custom title bar detection mechanism to identify desired websites in victims’ browsers and perform malicious actions.

The threat actors behind JanelaRAT campaigns continuously update the infection chain and malware versions by adding new features. Kaspersky solutions detect this threat as Trojan. Script. Generic and Backdoor. MSIL. Agent. gen. Initial infection JanelaRAT campaigns involve a multi-stage infection chain.

Read Original Source