BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Rust VENON Malware Targets Brazilian Banking Apps

New Rust banking Trojan VENON targets Brazil, uses AI and hijacks shortcuts to steal credentials.

  • A new Rust-based banking Trojan named VENON is targeting Brazilian users, departing from the region’s typical Delphi-based malware.
  • The malware is sophisticated, using nine evasion techniques and shortcut hijacking to steal credentials from 33 financial and crypto platforms.
  • The code suggests the developer used generative AI to translate known banking Trojan capabilities into the Rust language.
  • Its discovery coincides with a separate WhatsApp-based worm campaign distributing other banking malware like Astaroth in Brazil.

Brazilian cybersecurity firm ZenoX revealed in March 2026 that a new Windows banking Trojan, codenamed VENON, has emerged, written in the Rust programming language. This discovery marks a significant shift from the Delphi-based malware families traditionally linked to Latin American cybercrime.

- Advertisement -

The malware first appeared last month and shares key behaviors with established regional Trojans like Grandoreiro. VENON features banking overlay logic, active window monitoring, and a mechanism for hijacking system shortcuts.

ZenoX said the Rust code structure suggests a developer familiar with existing threats possibly used generative AI to rewrite functionalities. The campaign is suspected to use social engineering lures, like ClickFix, to deliver its payload via a multi-stage PowerShell infection chain.

VENON employs nine sophisticated evasion techniques before activating. It then retrieves a configuration from a Google Cloud Storage URL and establishes a WebSocket connection to its command server.

Its hijacking mechanism specifically targets Brazil’s Itaú banking application by replacing legitimate shortcuts. Consequently, this redirects victims to attacker-controlled pages designed for credential theft.

- Advertisement -

The malware monitors for 33 targeted financial institutions and digital asset platforms. It springs into action only when a victim accesses one of these services, deploying fake overlays to capture login data.

Meanwhile, a separate but related threat exploits the ubiquity of WhatsApp in Brazil. A worm named SORVEPOTEL is delivered via the platform’s desktop web version, as detailed by Blackpoint Cyber.

Blackpoint Cyber said a single hijacked WhatsApp message could draw victims into a chain deploying malware like Astaroth. This combination of local automation and permissive environments allowed the threats to establish themselves with minimal friction.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Justin Sun’s $70M Frozen in Trump-Linked Crypto Project

Justin Sun had approximately 544 million World Liberty Financial tokens frozen in September 2024...

BTC to Bottom at $55K in 2026 Before Bull Run

New analysis from CryptoQuant predicts Bitcoin will bottom near $55,000-$60,000 in late 2026.The forecast...

Marimo Critical Flaw Exploited in Under 10 Hours

A critical security vulnerability (CVE-2026-39987) in the open-source Python notebook Marimo was exploited within...

Bitcoin QuantumSafe Plan Costly, No Fork Needed

A researcher has proposed a quantum-safe Bitcoin transaction scheme that works without changing the...

TD Cowen Downgrades MSTR Target, Calls Sharplink a ‘Buy’

TD Cowen has initiated coverage of Ethereum treasury firm Sharplink with a "buy" rating,...

Must Read

A Beginner’s Guide To Cryptocurrency Mining

Cryptocurrency is considered one of the most popular forms of financial assets today. Many of these digital assets operate within blockchain technology which works...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading