Tag: Brazil

JanelaRAT Malware Targets Latin American Banks with 14,739 Attacks in Brazil in 2025
News

JanelaRAT Malware Targets Latin American Banks with 14,739 Attacks in Brazil in 2025

A malware family known as JanelaRAT has continued to attack banks and financial organizations in Latin American nations like Brazil and Mexico. JanelaRAT, a modified version of BX RAT, is known to track mouse inputs, log keystrokes, capture screenshots, gather system metadata, and steal cryptocurrencies and financial data linked to particular financial companies. According to a report released today by Kaspersky, one of the main distinctions between these trojans is that JanelaRAT employs a unique title bar detection algorithm to locate desired websites in victims' browsers and carry out destructive actions. The threat actors responsible for JanelaRAT operations add new functionality to malware versions and the infection chain on a regular basis. Up to 14,739 attacks were reporte...
WhatsApp Worm Spreads Astaroth Banking Trojan Across Brazil via Contact Auto-Messaging
News

WhatsApp Worm Spreads Astaroth Banking Trojan Across Brazil via Contact Auto-Messaging

Cybersecurity experts have revealed information on a new campaign that targets Brazil by using WhatsApp as a distribution vector for the Astaroth Windows banking trojan. The Acronis Threat Research Unit has given the campaign the code name Boto Cor-de-Rosa. According to a report sent to The Hacker News by the cybersecurity business, the malware obtains the victim's WhatsApp contact list and automatically sends malicious messages to each contact in order to propagate the infection. The recently introduced WhatsApp-based worm module is fully developed in Python, demonstrating the threat actors' increasing usage of multi-language modular components, even though the core Astaroth payload is still written in Delphi and its installer uses Visual Basic script read more about WhatsApp Wo...
WhatsApp Malware ‘Maverick’ Hijacks Browser Sessions to Target Brazil’s Biggest Banks
News

WhatsApp Malware ‘Maverick’ Hijacks Browser Sessions to Target Brazil’s Biggest Banks

Threat hunters have identified similarities between Coyote, a banking malware, and Maverick, a newly revealed malicious program spread through WhatsApp. As stated in a report by CyberProof, the two strains of malware are developed using .NET, aimed at Brazilian users and financial institutions, and possess the same functions for decryption, targeting banking URLs and observing banking apps. Of greater significance, both can disseminate via WhatsApp Web. Trend Micro documented Maverick for the first time in early last month, linking it to a threat actor named Water Saci. The campaign consists of two elements: An autonomous malware known as SORVEPOTEL that disseminates through the desktop web version of WhatsApp and is utilized to send a ZIP file with the Maverick payload. The mali...
Initial Access Brokers Target Brazil Execs via NF-e Spam and Legit RMM Trials
News

Initial Access Brokers Target Brazil Execs via NF-e Spam and Legit RMM Trials

Researchers studying cybersecurity are alerting people to a new campaign that has been using trial versions of commercial remote monitoring and management (RMM) software since January 2025 to target Portuguese-speaking users in Brazil. According to a report released Thursday by Cisco Talos researcher Guilherme Venere, the spam message leverages the Brazilian electronic invoice system, NF-e, as a lure to trick consumers into clicking hyperlinks and accessing harmful files hosted in Dropbox. In order to deceive victims into clicking on fake Dropbox links that lead to a binary installer for the RMM program, the attack chains start with well constructed spam emails that seem to be from financial institutions or mobile phone carriers and warn of past-due bills or unpaid invoices. PDQ ...
Meta Halts AI Use in Brazil Following Data Protection Authority’s Ban
News

Meta Halts AI Use in Brazil Following Data Protection Authority’s Ban

After Brazil's data protection authorities imposed a preliminary prohibition in opposition to Meta's new privacy policy, Meta decided to halt the usage of generative artificial intelligence (GenAI) in that country. News agency Reuters was the first to report on the development. In response to concerns raised by Brazil's National Data Protection Authority (ANPD) regarding the company's use of GenAI technology, the company said that it has chosen to halt the tools while it holds negotiations with the agency. The social media giant's new privacy policy, which gave it access to users' personal data to train its GenAI systems, was immediately suspended by ANPD earlier this month read more Meta Halts AI Use in Brazil Following Data Protection Authority's Ban. Get up to date on the&n...
Brazil Halts Meta’s AI Data Processing Amid Privacy Concerns
News

Brazil Halts Meta’s AI Data Processing Amid Privacy Concerns

Autoridade Nacional de Proteção de Dados (ANPD), Brazil's data protection body, has temporarily prohibited Meta from using user data to build its artificial intelligence (AI) algorithms. According to the ANPD, it discovered proof of the processing of personal data based on insufficient legal justifications, a lack of openness, restrictions on data subjects' rights, and hazards to minors. The ruling comes in response to the social media behemoth's modification of its terms, which permits it to use Facebook, Instagram, and Messenger's public content for AI training. Human Rights Watch revealed in a recent research that links to identifying images of Brazilian children were present in LAION-5B, one of the largest image-text datasets used to train AI models. This put the children at ...
Grandoreiro Banking Trojan Hits Brazil as Smishing Scams Surge in Pakistan
News

Grandoreiro Banking Trojan Hits Brazil as Smishing Scams Surge in Pakistan

The Smishing Triad is a threat actor that has expanded its reach outside the United States, the United Arab Emirates, Saudi Arabia, and the European Union. Its current target is Pakistan. Resecurity claimed in a study earlier this week that the group's most recent strategy entails delivering malicious messages to mobile carrier customers via iMessage and SMS on behalf of Pakistan Post. The intention is to steal their financial and personal data. The threat actors, who are thought to speak Chinese, are well-known for using stolen datasets that are sold on the dark web to send phony text messages that lure receivers into clicking on links pretending to tell them that their product has not arrived as expected and that they should alter their address read more Grandoreiro Banking Trojan...
8Base Ransomware Threatens U.S. and Brazilian Businesses
News

8Base Ransomware Threatens U.S. and Brazilian Businesses

A "massive spike in activity" in May and June 2023 has been attributed to the 8Base ransomware threat, which has been active covertly for over a year. According to researchers at VMware Carbon Black Deborah Snyder and Fae Carlisle, "the group uses encryption combined with 'name-and-shame' techniques to compel their victims to pay their ransoms." "8Base has a pattern of opportunistic compromise with recent victims spanning across various industries," the report states. As of May 2023, 8Base had been connected to 67 attacks, according to data obtained by Malwarebytes and NCC Group, with about 50% of the victims working in the commercial services, manufacturing, and construction sectors read more 8Base Ransomware Threatens U.S. and Brazilian Businesses. Stay one step ahead of cyber ...
Pixpirate: New Android Banking Trojan Targeting Brazilian Financial Institutions
Risk, Security

Pixpirate: New Android Banking Trojan Targeting Brazilian Financial Institutions

A new Android banking trojan has targeted Brazilian financial institutions with the intention of defrauding them using the PIX payments system. The malware is being tracked as PixPirate by the Italian cybersecurity firm Cleafy, which found it between the end of 2022 and the beginning of 2023. According to researchers Francesco Iubatti and Alessandro Strino, "PixPirate belongs to the newest generation of Android banking trojans, as it can perform ATS (Automatic Transfer System), enabling attackers to automate the insertion of a malicious money transfer over the Instant Payment platform Pix, adopted by multiple Brazilian banks read the complete article Pixpirate: New Android Banking Trojan Targeting Brazilian Financial Institutions.