N40
- First seen
- 2019-03-01 00:00:00
- Malware type
- botnet
- Family
- Malware family
- Profile updated
- 2026-07-07 15:13:03
Targeted industries: financial-services
Targeted regions: country_code:br country_code:ar country_code:mx
Context
Botnet with focus on banks in Latin America and South America. Relies on DLL Sideloading attacks to execute malicious DLL files. Uses legitimate VMWare executable in attacks. As of March 2019, the malware is under active development with updated versions coming out on persistent basis.
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.N40 (report)
- slideshare.net — N40 The Botnet Created In Brazil Which Evolves To Attack The Chilean Banking Sector (report)
- blog.en.elevenpaths.com — New Report Malware Attacks Chilean (report)
- reversingminds-blog.logdown.com — 7807545 Analysis Of Advanced Brazilian Banker Malware (report)
- socprime.com — Attackers Exploit Dll Hijacking To Bypass Smartscreen (report)