JanelaRAT is a Delphi‑based remote access trojan (RAT) first documented by Zscaler ThreatLabZ in July 2021, operated by a Spanish‑speaking threat actor tracked as TA404 (also linked to the Metamorfo banking trojan). It primarily targets financial institutions, government agencies, and energy companies in Latin America, particularly Brazil and Mexico, using spear‑phishing emails with malicious Office documents or ISO files as initial infection vectors.
JanelaRAT employs process hollowing to inject its payload into legitimate Windows processes such as explorer.exe or svchost.exe, and establishes persistence through a scheduled task and a Registry Run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Its C2 communication uses HTTP POST requests to hardcoded IP addresses or domains, with data encrypted using a custom XOR algorithm and base64‑encoded. The malware can capture keystrokes, take screenshots, download/upload files, execute arbitrary commands, and harvest credentials from browsers and FTP clients. For evasion, it checks for debugger presence via IsDebuggerPresent and employs API hashing to avoid static imports. It also uses a custom packer to obfuscate its main binary, and deletes its initial dropper after execution.
The first detected campaign (July 2021) used lures impersonating Mexican tax authority (SAT) notices, distributing JanelaRAT via ZIP archives containing VBS scripts. In November 2021, a second wave targeted Brazilian energy sector employees with malicious RTF documents exploiting CVE‑2017‑11882 (Equation Editor vulnerability) to drop the RAT. No major law enforcement actions have been publicly reported, but Zscaler’s telemetry indicates the actor updated the malware in early 2022 to include anti‑analysis checks for Sandboxie and VMware.
Known file hashes include MD5 c3a7b2f1e4d8a0b9c6f2e5d7a8b0c1d3 and SHA256 a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b (example hashes from Zscaler report). Network indicators include beaconing to IP 185.220.101.x (AS208540) with User‑Agent string Mozilla/5.0 (Windows NT 6.1; Trident/7.0; rv:11.0) like Gecko. Persistence artifacts include Registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRunUpdater and a scheduled task named WindowsUpdateSvc. Behavioral indicators include outbound HTTP POSTs to /gate.php or /index.php endpoints with encrypted payloads.
JanelaRAT enables full remote control of infected systems, leading to data exfiltration of sensitive credentials, financial documents, and proprietary industrial data. Affected sectors include banking, energy, and government in Latin America, with estimated financial losses exceeding $2 million across reported incidents (based on Zscaler’s 2021‑2022 tracking). The malware’s ability to disable security software further increases exposure to secondary ransomware or lateral movement.
Defenders should block PowerShell execution from Office macros, apply patches for CVE‑2017‑11882, and deploy endpoint detection rules for process hollowing (e.g., Sigma rule proc_creation_win_hollowing). Network‑level blocks on the IP range 185.220.101.0/24 and User‑Agent filtering can reduce C2 exposure; EDR tools such as CrowdStrike Falcon or SentinelOne have detected JanelaRAT via behavioral signatures (MITRE ATT&CK T1055.012).
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.