Brazilian Banks Targeted by New AllaKore RAT Variant Called AllaSenha
A new campaign called AllaSenha targets Brazilian banking institutions with a customized version of the Windows-based AllaKore remote access trojan (RAT).
According to a technical investigation by French cybersecurity company HarfangLab, the virus is "specifically aimed at stealing credentials that are required to access Brazilian bank accounts, [and] leverages Azure cloud as command-and-control (C2) infrastructure."
Banks like Banco do Brasil, Bradesco, Banco Safra, Caixa Econômica Federal, Itaú Unibanco, Sicoob, and Sicredi are among the targets of the campaign. The first access vector suggests that malicious links are used in phishing mails, however this is not proved conclusively.
The attack originates from a malicious Windows shortcut (LNK) file that has been hosted on a Web...

