JanelaRAT Malware Targets Latin American Banks with 14,739 Attacks in Brazil in 2025
2026-04-14T01:24:14Z•a1bde24d3aedcc14ec7dac1a5282a6d556639e993eac59973ad2b98049d9b42c
APT28APT37BX RATCPUID compromiseCVE-2026-34621CVE-2026-39987Chaos malwareEngageLab SDKGlassWormIDE compromiseJanelaRATLucidRookMasjesuPRISMEXRCERokRATSTX RATSmart Slider backdoorW3LLbotnetbrowser securitycredential theftphishingsupply-chain compromisezero-day
What happened
Collection of April 2026 security reports describing widespread active exploitation, supply-chain compromises, large-scale phishing/fraud operations, and targeted APT campaigns. Notable items: JanelaRAT (BX RAT variant) conducted 14,739 attacks against Brazilian banks in 2025; FBI and Indonesian police dismantled the W3LL phishing infrastructure tied to >$20M fraud attempts and arrested an alleged developer; actively exploited Acrobat Reader vulnerability (CVE-2026-34621, CVSS 8.6) and a Marimo pre-auth RCE (CVE-2026-39987, CVSS 9.3) were observed in the wild; CPUID site was abused to deliver/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- a1bde24d3aedcc14ec7dac1a5282a6d556639e993eac59973ad2b98049d9b42c
- Enrichment time
- 2026-04-14T01:24:14Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.