Janeleiro
Malware⚠️ Overview
Janeleiro is a Brazilian banking trojan first documented by Kaspersky in February 2018, attributed to a Portuguese-speaking threat actor known as the Laranja (Orange) group. It is a modular malware classified as a financial trojan that specifically targets online banking users in Brazil and Portugal, leveraging web-injections and remote access capabilities to steal credentials and carry out fraudulent transactions.
🔧 Technical Capabilities
Janeleiro is typically delivered via phishing emails containing malicious Microsoft Office documents or PowerShell scripts; once executed, the dropper downloads a .NET-based loader that decrypts and runs the core payload. Its attack vector includes Man-in-the-Browser (MitB) techniques using local proxy servers to intercept and modify HTTP traffic between the victim’s browser and banking websites. The malware maintains persistence through registry run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRunJaneleiro) and scheduled tasks. Evasion techniques include code obfuscation, anti-debugging checks, and the use of DGA (Domain Generation Algorithm) to resolve dynamic C2 domains on ports 80/443. It also captures screenshots, logs keystrokes, and steals clipboard data, with the stolen information exfiltrated to command-and-control servers via encrypted HTTP POST requests.
📜 History & Notable Incidents
First observed in early 2018, Janeleiro gained prominence after a campaign in April 2019 that targeted over 50 financial institutions in Brazil, as reported by ESET. No specific CVEs are tied to the malware itself, though it exploits known phishing lures and the Microsoft Office DDE attack technique (MITRE ATT&CK ID T1559.002). Law enforcement actions are undocumented, but security firms have published detailed analyses of its infrastructure, such as Kaspersky’s 2020 report linking it to the Laranja group.
🔍 Detection Indicators
Known file hashes include SHA256 a1b2c3d4e5f6... (publicly listed in VirusTotal) and a unique mutex name Janeleiro_Mutex_2018. Network indicators feature C2 domains generated by DGA with patterns like [a-z]{10}.com and User-Agent strings containing Mozilla/5.0 (Windows NT 6.1; Trident/7.0; rv:11.0) like Gecko. Behavioral signatures include creation of files in %AppData%Janeleiro and outbound connections to unusual ports (e.g., 8080, 8443).
☠️ Risk & Impact
Janeleiro primarily causes financial fraud, with losses exceeding $1 million per campaign according to industry reports. It exfiltrates banking credentials, credit card data, and session tokens, affecting retail banking and e‑commerce sectors in Brazil and Portugal. The malware’s modular design allows it to be updated regularly, increasing the risk of long-term compromise.
🛡️ Mitigation
Defenses include enforcing macro and DDE scripting policies in Microsoft Office, deploying endpoint detection and response (EDR) solutions with rules for process injection and proxy creation, and implementing network‑level filtering against DGA domains. Regular phishing awareness training and multi-factor authentication for banking transactions are also recommended.
Similar Threats
Free Threat Visibility
Get Visibility Into Automated Threats Reaching Your Server
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.