JanelaRAT: LATAM Bank Thieves' Window into Your Wallet [Analysis]
Imagine clicking a 'pending invoice' email, only for it to pry open your banking app like a digital crowbar. JanelaRAT is hitting LATAM hard, turning your PC into a thief's playground.
⚡ Key Takeaways
- JanelaRAT uses MSI droppers and DLL sideloading for stealthy persistence on Windows systems. 𝕏
- Custom browser title detection targets LATAM banks and crypto, enabling real-time fraud. 𝕏
- Evolving chains with obfuscation show threat actors outpacing basic detection tools. 𝕏
- Similar to Conficker's spread, it risks global expansion beyond Latin America. 𝕏
Worth sharing?
Get the best Cybersecurity stories of the week in your inbox — no noise, no spam.
Originally reported by Securelist (Kaspersky)