BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Rust VENON Malware Targets Brazilian Banking Apps

New Rust banking Trojan VENON targets Brazil, uses AI and hijacks shortcuts to steal credentials.

  • A new Rust-based banking Trojan named VENON is targeting Brazilian users, departing from the region’s typical Delphi-based malware.
  • The malware is sophisticated, using nine evasion techniques and shortcut hijacking to steal credentials from 33 financial and crypto platforms.
  • The code suggests the developer used generative AI to translate known banking Trojan capabilities into the Rust language.
  • Its discovery coincides with a separate WhatsApp-based worm campaign distributing other banking malware like Astaroth in Brazil.

Brazilian cybersecurity firm ZenoX revealed in March 2026 that a new Windows banking Trojan, codenamed VENON, has emerged, written in the Rust programming language. This discovery marks a significant shift from the Delphi-based malware families traditionally linked to Latin American cybercrime.

- Advertisement -

The malware first appeared last month and shares key behaviors with established regional Trojans like Grandoreiro. VENON features banking overlay logic, active window monitoring, and a mechanism for hijacking system shortcuts.

ZenoX said the Rust code structure suggests a developer familiar with existing threats possibly used generative AI to rewrite functionalities. The campaign is suspected to use social engineering lures, like ClickFix, to deliver its payload via a multi-stage PowerShell infection chain.

VENON employs nine sophisticated evasion techniques before activating. It then retrieves a configuration from a Google Cloud Storage URL and establishes a WebSocket connection to its command server.

Its hijacking mechanism specifically targets Brazil’s Itaú banking application by replacing legitimate shortcuts. Consequently, this redirects victims to attacker-controlled pages designed for credential theft.

- Advertisement -

The malware monitors for 33 targeted financial institutions and digital asset platforms. It springs into action only when a victim accesses one of these services, deploying fake overlays to capture login data.

Meanwhile, a separate but related threat exploits the ubiquity of WhatsApp in Brazil. A worm named SORVEPOTEL is delivered via the platform’s desktop web version, as detailed by Blackpoint Cyber.

Blackpoint Cyber said a single hijacked WhatsApp message could draw victims into a chain deploying malware like Astaroth. This combination of local automation and permissive environments allowed the threats to establish themselves with minimal friction.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

U.S. Crypto Clarity Act Nears Key Senate Deal

Coinbase Chief Legal Officer Paul Grewal announced lawmakers are nearing a resolution on disputed...

Ex-FTX engineer Nishad Singh fined $3.7 million

Former FTX head of engineering Nishad Singh settled a Commodity Futures Trading Commission (CFTC)...

Tether’s Jesse Spiro to Chair $100M Crypto Super PAC

Tether's Head of Government Affairs, Jesse Spiro, will chair the crypto-funded Fellowship PAC ahead...

CERT-UA Impersonated, New RAT Attack Hits Ukraine

The Computer Emergency Response Team of Ukraine (CERT-UA) was impersonated in a phishing campaign...

Binance Launches Oil and Gas Futures with 100x Leverage

Binance has officially launched trading for oil and natural gas futures contracts, completing its...

Must Read

How to Choose a Cryptocurrency Exchange: Major Risks and Expert Advice

During the bitcoin frenzy, in late 2017, Coinbase, one of the key players in the global cryptocurrency market, stopped trading operations. At a point...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading