N40

First seen
2019-03-01 00:00:00
Malware type
botnet
Family
Malware family
Profile updated
2026-07-07 15:13:03

Targeted industries: financial-services

Targeted regions: country_code:br country_code:ar country_code:mx

Context

Botnet with focus on banks in Latin America and South America. Relies on DLL Sideloading attacks to execute malicious DLL files. Uses legitimate VMWare executable in attacks. As of March 2019, the malware is under active development with updated versions coming out on persistent basis.

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.N40 (report)
  • slideshare.net — N40 The Botnet Created In Brazil Which Evolves To Attack The Chilean Banking Sector (report)
  • blog.en.elevenpaths.com — New Report Malware Attacks Chilean (report)
  • reversingminds-blog.logdown.com — 7807545 Analysis Of Advanced Brazilian Banker Malware (report)
  • socprime.com — Attackers Exploit Dll Hijacking To Bypass Smartscreen (report)

External references