JanelaRAT
- First seen
- 2023-05-01 00:00:00
- Malware type
- rat
- Family
- Malware family
- Last IoC activity
- 2026-07-21 22:31:16
- Profile updated
- 2026-07-07 15:07:40
Targeted industries: financial-services
Targeted regions: country_code:br
Context
According to Zscaler, JanelaRAT is a heavily modified variant of BX RAT. Its focus is set on harvesting LATAM financial data and its method of extracting window titles for transmission underscores its targeted and stealthy nature. With an adaptive approach utilizing dynamic socket configuration and exploiting DLL side-loading from trusted sources, JanelaRAT poses a significant threat.
Detection coverage
- 2 YARA rules
Detection rules
- DITEKSHEN_MALWARE_Win_Janelarat (yara-rule)
- SEKOIA_Win_Malware_Janelarat_Strings (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Janela Rat (report)
- medium.com — Janela Rat And A Stealer Extension Delivered Together E274469A7Df8 (report)
- zscaler.com — Janelarat Repurposed Bx Rat Variant Targeting Latam Fintech (report)