Cybersecurity researchers have revealed details of VENON , a new banking malware targeting users in Brazil and written in the Rust language. It is an interesting departure from other well-known Delphi -based malware families associated with the Latin American cybercrime ecosystem

The malware, which is designed to infect Windows and was first discovered last month, has been codenamed VENON by Brazilian cybersecurity firm ZenoX.
VENON shares behaviors consistent with established banking trojans targeting the region, such as Grandoreiro, Mekotio, and Coyote: banking overlay logic, active window monitoring, and shortcut (LNK) hijacking mechanism.
See also: SocksEscort Botnet Dismantled by Law Enforcement Authorities
The malware has not been linked to any known group or campaign. However, a previous version, dating back to January 2026, was found to expose full paths from the malware creator’s development environment . The paths repeatedly refer to a Windows machine username “byst4” (e.g., “C:\Users\byst4\…”).
“ The structure of the Rust code exhibits patterns that suggest a developer familiar with the capabilities of existing Latin American banking trojans. But he used generative AI to rewrite and extend these functions in Rust, a language that requires significant technical expertise to use at the observed level of complexity ,” ZenoX said

How is the Venon banking trojan distributed?
VENON is distributed via a sophisticated infection chain that uses DLL side-loading to launch a malicious DLL. The campaign is believed to exploit social engineering techniques such as ClickFix to convince users to download a ZIP file containing the payloads via a PowerShell script.
See also: Hive0163 uses AI malware Slopoly in ransomware attacks
Once the DLL is executed, it performs nine evasion techniques, including anti-sandbox checks, indirect syscalls, ETW bypass, AMSI bypass. This is where the actual initiation of any malicious action occurs. It also connects to a Google Cloud Storage URL to retrieve a configuration, install a scheduled task, and establish a WebSocket connection to the command and control (C2) server.
At the same time, two Visual Basic Script blocks are extracted from the DLL that implement a shortcut hijacking mechanism , which exclusively targets the Itaú banking application . The components work by replacing legitimate system shortcuts with forged versions that redirect the victim to a website under the control of the threat actor.
The attack also supports an uninstall to undo the modifications, suggesting that the operation can be remotely controlled by the operator to restore the shortcuts to their original state and cover up the traces.
See also: 6 new Android malware targets banking apps

In total, the VENON banking malware is equipped to target 33 financial institutions and digital asset by monitoring the window title and active browser domain. It is only activated when the targeted applications or websites are opened to facilitate credential theft by providing false overlays.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
