JanelaRAT

First seen
2023-05-01 00:00:00
Malware type
rat
Family
Malware family
Last IoC activity
2026-07-21 22:31:16
Profile updated
2026-07-07 15:07:40

Targeted industries: financial-services

Targeted regions: country_code:br

Context

According to Zscaler, JanelaRAT is a heavily modified variant of BX RAT. Its focus is set on harvesting LATAM financial data and its method of extracting window titles for transmission underscores its targeted and stealthy nature. With an adaptive approach utilizing dynamic socket configuration and exploiting DLL side-loading from trusted sources, JanelaRAT poses a significant threat.

Detection coverage

  • 2 YARA rules

Detection rules

  • DITEKSHEN_MALWARE_Win_Janelarat (yara-rule)
  • SEKOIA_Win_Malware_Janelarat_Strings (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Janela Rat (report)
  • medium.com — Janela Rat And A Stealer Extension Delivered Together E274469A7Df8 (report)
  • zscaler.com — Janelarat Repurposed Bx Rat Variant Targeting Latam Fintech (report)

External references