# JanelaRAT 2026 Campaign: Updated Brazilian Banking Trojan Targeting Latin American Financial Sector via DLL Side-Loading

> Kaspersky GReAT has disclosed a new JanelaRAT campaign using an updated multi-stage infection chain, refined DLL side-loading abuse, and expanded overlay targets against additional LATAM banks and crypto exchanges. Originally documented in 2023, JanelaRAT returns with improved C2 resilience, Portuguese-language artifacts, and new window-title monitoring logic designed to steal credentials, one-time passwords, and PIX transfer data from banking customers across Brazil, Mexico, Colombia, Chile, and Peru.

- **Published:** 2026-04-13T12:00:00Z
- **Last reviewed:** 2026-04-13T12:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0353
- **ID:** TL-2026-0353
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Actor:** JanelaRAT Operators (Brazil)
- **Detections:** 9 · **IOCs:** 20 (full data via the Threadlinqs MCP server — Purple tier)

## Description

JanelaRAT is a banking Remote Access Trojan originally documented by Zscaler ThreatLabz in August 2023 and attributed to a Portuguese-speaking threat cluster operating out of Brazil. The name comes from the Portuguese word for 'window' (janela), a reference to the malware's core surveillance technique: it continuously monitors foreground window titles to detect when the victim opens a targeted banking website or crypto exchange, then triggers credential and overlay theft logic.

The 2026 campaign documented by Kaspersky's Global Research and Analysis Team (GReAT) on 2026-04-13 shows a substantially updated variant with the following changes: (1) a new multi-stage Visual Basic Script loader delivered via malvertising and compromised legitimate Brazilian websites, (2) abuse of a legitimate signed VMware helper binary (VMwareXferlogs.exe) as a DLL side-loading host for a malicious glib-2.0.dll stager, (3) AES-256 encrypted payload staging retrieved from compromised WordPress hosts and AWS S3 buckets, (4) expansion of target window-title list from ~40 to over 120 LATAM banks and major crypto exchanges including Binance LATAM, Mercado Bitcoin, and Bitso, (5) addition of PIX transfer hijacking logic specific to Brazilian instant-payment flows, and (6) Cobalt Strike post-exploitation deployment on a subset of high-value compromises.

The infection chain begins when a victim is directed to a typosquatted or compromised Brazilian news/tax/NF-e website hosting a fake Adobe Reader or tax document update prompt. The download is an MSI installer that drops a digitally signed VMware binary alongside a trojanized glib-2.0.dll. DLL side-loading executes a shellcode stager which resolves C2 infrastructure via DGA-seeded dynamic DNS on Duck DNS and No-IP, then pulls down a second-stage JanelaRAT payload written in Delphi/C# hybrid code.

Once resident, JanelaRAT hooks GetForegroundWindow and GetWindowTextW on a polling loop, comparing window titles to an embedded Portuguese/Spanish-language target list. On a match, it launches screen capture of the banking UI, activates keylogging, and overlays phishing windows that mimic the legitimate bank's 2FA/OTP prompts. Stolen data is buffered locally, AES encrypted, and exfiltrated via HTTPS POST to Brazilian-hosted C2 VPS instances, with fallback over Telegram bot API.

Kaspersky links the updated cluster to the same actor group responsible for earlier JanelaRAT activity and Guildma/Astaroth campaigns, with shared TTPs around DLL side-loading and LATAM bank targeting. The operation remains primarily financially motivated but has begun layering in Cobalt Strike for potential lateral movement inside corporate banking networks, a significant escalation from pure endpoint credential theft.

## MITRE ATT&CK

- T1583 Acquire Infrastructure
- T1583.001 Acquire Infrastructure: Domains
- T1584 Compromise Infrastructure
- T1608.001 Stage Capabilities: Upload Malware
- T1189 Drive-by Compromise
- T1566.002 Phishing: Spearphishing Link
- T1204.002 User Execution: Malicious File
- T1059.005 Command and Scripting Interpreter: Visual Basic
- T1218.007 System Binary Proxy Execution: Msiexec
- T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
- T1053.005 Scheduled Task/Job: Scheduled Task
- T1574.001 DLL
- T1027 Obfuscated Files or Information
- T1036.005 Match Legitimate Resource Name or Location
- T1553.002 Subvert Trust Controls: Code Signing
- T1056.001 Input Capture: Keylogging
- T1056.002 Input Capture: GUI Input Capture
- T1555.003 Credentials from Password Stores: Credentials from Web Browsers
- T1082 System Information Discovery
- T1010 Application Window Discovery
- T1057 Process Discovery
- T1113 Screen Capture
- T1115 Clipboard Data
- T1071.001 Application Layer Protocol: Web Protocols
- T1102.002 Web Service: Bidirectional Communication
- T1568.002 Dynamic Resolution: Domain Generation Algorithms
- T1573.001 Encrypted Channel: Symmetric Cryptography
- T1041 Exfiltration Over C2 Channel
- T1567 Exfiltration Over Web Service
- T1657 Financial Theft

## Sources

- [JanelaRAT: a financial threat targeting users in Latin America](https://securelist.com/janelarat-financial-threat-in-latin-america/119332/)
- [Zscaler ThreatLabz: JanelaRAT Targets LATAM FinTech Users](https://www.zscaler.com/blogs/security-research/janelarat-repurposed-bx-rat-variant-targeting-latam-fintech)
- [MITRE ATT&CK Technique T1574.002 DLL Side-Loading](https://attack.mitre.org/techniques/T1574/002/)
- [CISA Advisory on Banking Trojan Malvertising Trends](https://www.cisa.gov/news-events/cybersecurity-advisories/banking-trojan-malvertising)
- [Kaspersky GReAT LATAM Financial Threats Report 2026](https://securelist.com/latam-financial-threats-2026/)
- [Sigma Rule: Suspicious VMwareXferlogs.exe Child Process](https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_susp_vmwarexferlogs.yml)
- [Trend Micro: Guildma/Astaroth and Related LATAM Banker Ecosystem](https://www.trendmicro.com/en_us/research/24/c/guildma-astaroth-latam.html)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0353
