JanelaRAT Malware Targets Latin American Banks with 14,739 Attacks in Brazil in 2025

2026-04-14T01:24:14Za1bde24d3aedcc14ec7dac1a5282a6d556639e993eac59973ad2b98049d9b42c
APT28APT37BX RATCPUID compromiseCVE-2026-34621CVE-2026-39987Chaos malwareEngageLab SDKGlassWormIDE compromiseJanelaRATLucidRookMasjesuPRISMEXRCERokRATSTX RATSmart Slider backdoorW3LLbotnetbrowser securitycredential theftphishingsupply-chain compromisezero-day

What happened

Collection of April 2026 security reports describing widespread active exploitation, supply-chain compromises, large-scale phishing/fraud operations, and targeted APT campaigns. Notable items: JanelaRAT (BX RAT variant) conducted 14,739 attacks against Brazilian banks in 2025; FBI and Indonesian police dismantled the W3LL phishing infrastructure tied to >$20M fraud attempts and arrested an alleged developer; actively exploited Acrobat Reader vulnerability (CVE-2026-34621, CVSS 8.6) and a Marimo pre-auth RCE (CVE-2026-39987, CVSS 9.3) were observed in the wild; CPUID site was abused to deliver/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
a1bde24d3aedcc14ec7dac1a5282a6d556639e993eac59973ad2b98049d9b42c
Enrichment time
2026-04-14T01:24:14Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · JanelaRAT Malware Targets Latin American Banks with 14,739 Attacks in Brazil in 2025 · Baitaphish