HomeSecurityRust-based VENON malware targets 33 banks

Rust-based VENON malware targets 33 banks

Cybersecurity researchers have revealed details of VENON , a new banking malware targeting users in Brazil and written in the Rust language. It is an interesting departure from other well-known Delphi -based malware families associated with the Latin American cybercrime ecosystem

VENON malware

The malware, which is designed to infect Windows and was first discovered last month, has been codenamed VENON by Brazilian cybersecurity firm ZenoX.

VENON shares behaviors consistent with established banking trojans targeting the region, such as Grandoreiro, Mekotio, and Coyote: banking overlay logic, active window monitoring, and shortcut (LNK) hijacking mechanism.

See also: SocksEscort Botnet Dismantled by Law Enforcement Authorities

The malware has not been linked to any known group or campaign. However, a previous version, dating back to January 2026, was found to expose full paths from the malware creator’s development environment . The paths repeatedly refer to a Windows machine username “byst4” (e.g., “C:\Users\byst4\…”).

“ The structure of the Rust code exhibits patterns that suggest a developer familiar with the capabilities of existing Latin American banking trojans. But he used generative AI to rewrite and extend these functions in Rust, a language that requires significant technical expertise to use at the observed level of complexity ,” ZenoX said

Rust-based VENON malware targets 33 banks

How is the Venon banking trojan distributed?

VENON is distributed via a sophisticated infection chain that uses DLL side-loading to launch a malicious DLL. The campaign is believed to exploit social engineering techniques such as ClickFix to convince users to download a ZIP file containing the payloads via a PowerShell script.

See also: Hive0163 uses AI malware Slopoly in ransomware attacks

Once the DLL is executed, it performs nine evasion techniques, including anti-sandbox checks, indirect syscalls, ETW bypass, AMSI bypass. This is where the actual initiation of any malicious action occurs. It also connects to a Google Cloud Storage URL to retrieve a configuration, install a scheduled task, and establish a WebSocket connection to the command and control (C2) server.

At the same time, two Visual Basic Script blocks are extracted from the DLL that implement a shortcut hijacking mechanism , which exclusively targets the Itaú banking application . The components work by replacing legitimate system shortcuts with forged versions that redirect the victim to a website under the control of the threat actor.

The attack also supports an uninstall to undo the modifications, suggesting that the operation can be remotely controlled by the operator to restore the shortcuts to their original state and cover up the traces.

See also: 6 new Android malware targets banking apps

Rust-based VENON malware targets 33 banks

In total, the VENON banking malware is equipped to target 33 financial institutions and digital asset by monitoring the window title and active browser domain. It is only activated when the targeted applications or websites are opened to facilitate credential theft by providing false overlays.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS