33 Brazilian Banks Targeted by New Rust-Based VENON Credential Stealer
Mar 12, 2026 // 22:48 - Niko Dunn


Cybersecurity researchers from the Brazilian firm ZenoX have disclosed details of a new banking malware codenamed VENON that targets users of 33 financial institutions in Brazil. 

Key Technical Details

  • Rust-Based Development: Unlike most traditional Latin American banking trojans written in Delphi, VENON is written in Rust. This shift suggests a move toward more modern, performant, and cross-platform compatible codebases that can be harder for legacy security tools to detect.
  • Credential-Stealing Overlays: The malware continuously monitors for active windows or processes associated with specific banking portals, fintech services, and cryptocurrency platforms. When a match is found, it triggers a deceptive pop-up overlay to capture user credentials and transaction data.
  • Shortcut (LNK) Hijacking: VENON employs a mechanism to hijack application shortcuts, specifically targeting the Itaú app to redirect victims to attacker-controlled pages.
  • Capabilities: Once a system is infected, the malware allows operators to block the victim’s screen, log keystrokes, simulate mouse movements, and perform file operations. 

Targeting and Distribution

VENON is specifically localized for the Brazilian financial sector, targeting 33 major banks and cryptocurrency platforms like Mercado Bitcoin, Binance, Coinbase, and MetaMask. While no specific threat actor has been officially linked to the campaign, researchers discovered development paths in an early January 2026 version of the malware that exposed the author’s local environment. 

The emergence of VENON coincides with a broader trend in Brazil where threat actors are using WhatsApp Web to distribute worms like SORVEPOTEL, which can ultimately deploy various banking trojans. 

#banks  #brazilian  #credential  #new  #news  #rust-based  #stealer:  #targeted  #venon   —   News