Threat reportMalwareTL-2026-0353
JanelaRAT 2026 Campaign: Updated Brazilian Banking Trojan Targeting Latin American Financial Sector via DLL Side-Loading
JanelaRAT 2026 Campaign (TL-2026-0353), also tracked as Operation Janela 2026, is a high-severity malware campaign, first published 2026-04-13. It is attributed to JanelaRAT Operators (Brazil) with medium confidence, affects Microsoft Windows, maps to 30 MITRE ATT&CK techniques (T1010, T1027, T1036.005), and is covered by 9 detection rules and 20 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 30MITRE ATT&CK
- Actors
- 1JanelaRAT Operators
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 20Indicators of compromise
Key facts for TL-2026-0353
- Threat ID
- TL-2026-0353
- Also known as
- Operation Janela 2026, JanelaRAT v3, Janela Banking Trojan
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution
- JanelaRAT Operators
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Brazil
- Motivation
- FINANCIAL
- Target sectors
- financial, banking, cryptocurrency, fintech, consumer
- Target regions
- Brazil, Mexico, Colombia, Chile, Peru, Argentina, Latin America
- Detection rules
- 9
- Indicators of compromise
- 20
Malware and tooling in JanelaRAT 2026 Campaign
Malware and tooling: JanelaRAT, Cobalt Strike, Custom HTTPS beacon + Telegram Bot API fallback
How JanelaRAT 2026 Campaign works
Kaspersky GReAT has disclosed a new JanelaRAT campaign using an updated multi-stage infection chain, refined DLL side-loading abuse, and expanded overlay targets against additional LATAM banks and crypto exchanges. Originally documented in 2023, JanelaRAT returns with improved C2 resilience, Portuguese-language artifacts, and new window-title monitoring logic designed to steal credentials, one-time passwords, and PIX transfer data from banking customers across Brazil, Mexico, Colombia, Chile, and Peru.
JanelaRAT is a banking Remote Access Trojan originally documented by Zscaler ThreatLabz in August 2023 and attributed to a Portuguese-speaking threat cluster operating out of Brazil. The name comes from the Portuguese word for 'window' (janela), a reference to the malware's core surveillance technique: it continuously monitors foreground window titles to detect when the victim opens a targeted banking website or crypto exchange, then triggers credential and overlay theft logic.
The 2026 campaign documented by Kaspersky's Global Research and Analysis Team (GReAT) on 2026-04-13 shows a substantially updated variant with the following changes: (1) a new multi-stage Visual Basic Script loader delivered via malvertising and compromised legitimate Brazilian websites, (2) abuse of a legitimate signed VMware helper binary (VMwareXferlogs.exe) as a DLL side-loading host for a malicious glib-2.0.dll stager, (3) AES-256 encrypted payload staging retrieved from compromised WordPress hosts and AWS S3 buckets, (4) expansion of target window-title list from ~40 to over 120 LATAM banks and major crypto exchanges including Binance LATAM, Mercado Bitcoin, and Bitso, (5) addition of PIX transfer hijacking logic specific to Brazilian instant-payment flows, and (6) Cobalt Strike post-exploitation deployment on a subset of high-value compromises.
The infection chain begins when a victim is directed to a typosquatted or compromised Brazilian news/tax/NF-e website hosting a fake Adobe Reader or tax document update prompt. The download is an MSI installer that drops a digitally signed VMware binary alongside a trojanized glib-2.0.dll. DLL side-loading executes a shellcode stager which resolves C2 infrastructure via DGA-seeded dynamic DNS on Duck DNS and No-IP, then pulls down a second-stage JanelaRAT payload written in Delphi/C# hybrid code.
Once resident, JanelaRAT hooks GetForegroundWindow and GetWindowTextW on a polling loop, comparing window titles to an embedded Portuguese/Spanish-language target list. On a match, it launches screen capture of the banking UI, activates keylogging, and overlays phishing windows that mimic the legitimate bank's 2FA/OTP prompts. Stolen data is buffered locally, AES encrypted, and exfiltrated via HTTPS POST to Brazilian-hosted C2 VPS instances, with fallback over Telegram bot API.
Kaspersky links the updated cluster to the same actor group responsible for earlier JanelaRAT activity and Guildma/Astaroth campaigns, with shared TTPs around DLL side-loading and LATAM bank targeting. The operation remains primarily financially motivated but has begun layering in Cobalt Strike for potential lateral movement inside corporate banking networks, a significant escalation from pure endpoint credential theft.
MITRE ATT&CK techniques used in TL-2026-0353
Discovery
T1010 Application Window Discovery; T1057 Process Discovery; T1082 System Information Discovery
Defense Evasion
T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location
Exfiltration
T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service
Persistence
T1053.005 Scheduled Task/Job: Scheduled Task; T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
Credential Access
T1056.001 Input Capture: Keylogging; T1056.002 Input Capture: GUI Input Capture; T1555.003 Credentials from Password Stores: Credentials from Web Browsers
Execution
T1059.005 Command and Scripting Interpreter: Visual Basic; T1204.002 User Execution: Malicious File
Command and Control
T1071.001 Application Layer Protocol: Web Protocols; T1102.002 Web Service: Bidirectional Communication; T1568.002 Dynamic Resolution: Domain Generation Algorithms; T1573.001 Encrypted Channel: Symmetric Cryptography
Collection
T1113 Screen Capture; T1115 Clipboard Data
Initial Access
T1189 Drive-by Compromise; T1566.002 Phishing: Spearphishing Link
stealth
T1218.007 System Binary Proxy Execution: Msiexec; T1574.001 DLL
defense-impairment
T1553.002 Subvert Trust Controls: Code Signing
Resource Development
T1583 Acquire Infrastructure; T1583.001 Acquire Infrastructure: Domains; T1584 Compromise Infrastructure; T1608.001 Stage Capabilities: Upload Malware
Impact
Affected products and versions in JanelaRAT 2026 Campaign
- Microsoft — Windows
Vulnerable versions: 10; 11; Server 2016; Server 2019; Server 2022 - VMware (Broadcom) — VMware Tools (abused as side-loading host)
Vulnerable versions: all versions shipping VMwareXferlogs.exe - Various LATAM Banks — Online Banking Portals (targets of overlay theft)
Vulnerable versions: web and desktop banking clients - Various Crypto Exchanges — Binance LATAM, Mercado Bitcoin, Bitso, Foxbit (overlay targets)
Vulnerable versions: web clients
Remediation for JanelaRAT 2026 Campaign
Patches
- No vendor patches apply — JanelaRAT is malware, not a software vulnerability
- Ensure Windows, Microsoft Defender, and VMware Tools are fully patched to prevent unrelated LPE chains
Immediate actions
- Block known C2 domains and IP addresses at perimeter and DNS layer
- Block Duck DNS and No-IP dynamic DNS subdomains matching JanelaRAT DGA pattern where operationally feasible
- Hunt for VMwareXferlogs.exe executing from non-standard paths (anything outside %ProgramFiles%\VMware)
- Quarantine any glib-2.0.dll found adjacent to a VMware binary in user-writable paths
- Alert on unsigned MSI downloads from Brazilian news, tax (NF-e), and Adobe Reader lookalike domains
Workarounds
- Disable Visual Basic Script execution on endpoints via Software Restriction Policies or AppLocker
- Remove VMwareXferlogs.exe from systems that do not use VMware Tools
- Enforce browser SmartScreen and Google Safe Browsing to flag known malvertising redirects
Longer-term hardening
- Deploy EDR with behavioral DLL side-loading detection for Microsoft-signed and VMware-signed binaries
- Enable Windows Defender Application Control (WDAC) or AppLocker policies that validate DLL load paths, not just signatures
- Implement PowerShell and WScript/CScript command-line auditing via Sysmon event IDs 1 and 11
- Block outbound traffic to dynamic DNS providers from workstations that do not require it
- Deploy browser isolation or DNS filtering for Brazilian domains serving NF-e and tax-related content on endpoints that do not need them
Weaknesses (CWE) in JanelaRAT 2026 Campaign
Timeline of JanelaRAT 2026 Campaign
- Zscaler ThreatLabz publishes first public analysis of JanelaRAT, identifying it as a BX RAT variant targeting LATAM fintech users via DLL side-loading of VMware-signed binaries.
- Trend Micro publishes analysis linking JanelaRAT tradecraft to the broader Guildma/Astaroth LATAM banking malware ecosystem, noting shared DLL side-loading and Portuguese-language artifacts.
- CISA issues advisory highlighting a rise in banking trojan distribution via malvertising and typosquatted tax-document lures, which later proves to include JanelaRAT infrastructure.
- Kaspersky telemetry first detects updated JanelaRAT payloads carrying a new VBS loader and an expanded target window-title list covering 120+ LATAM banks and crypto exchanges.
- Kaspersky observes Cobalt Strike beacons deployed as a follow-on stage in a subset of JanelaRAT infections at corporate banking endpoints, indicating a shift toward hands-on-keyboard operations.
- Analysis of a fresh JanelaRAT sample reveals new Brazilian PIX instant-payment hijacking logic that rewrites destination keys during in-progress transfers.
- Threadlinqs Intelligence ingests the campaign and publishes TL-2026-0353 with MITRE ATT&CK mapping, IOCs, detections, and simulation guidance for defenders.
- Kaspersky GReAT publishes a full technical writeup on the updated JanelaRAT 2026 campaign via Securelist, including IOCs, TTPs, and victim geography.
- As of 2026-05-29, JanelaRAT remains an active, evolving LATAM banking trojan: Kaspersky GReAT's April 2026 Securelist report and The Hacker News confirm ongoing campaigns (14,739 attacks in Brazil, 11,695 in Mexico in 2025) via DLL side-loading and overlay session hijacking. No takedowns, arrests, or sinkholing reported; operators continuously update the infection chain.
Sources cited for JanelaRAT 2026 Campaign
- JanelaRAT: a financial threat targeting users in Latin America
- Zscaler ThreatLabz: JanelaRAT Targets LATAM FinTech Users
- MITRE ATT&CK Technique T1574.002 DLL Side-Loading
- CISA Advisory on Banking Trojan Malvertising Trends
- Kaspersky GReAT LATAM Financial Threats Report 2026
- Sigma Rule: Suspicious VMwareXferlogs.exe Child Process
- Trend Micro: Guildma/Astaroth and Related LATAM Banker Ecosystem
Detection coverage for TL-2026-0353
As of 2026-04-13, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0353 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.