Technology NewsTechnology NewsTechnology News
  • Computing
  • AI
  • Robotics
  • Cybersecurity
  • Electric Vehicle
  • Wearables
  • Gaming
  • Space
Reading: AllaSenha Targets Brazilian Banks
Share
Font ResizerAa
Technology NewsTechnology News
Font ResizerAa
Search
  • Computing
  • AI
  • Robotics
  • Cybersecurity
  • Electric Vehicle
  • Wearables
  • Gaming
  • Space
Follow US
  • Cookie Policy (EU)
  • Contact
  • About
© 2025 NEWSLINKER - Powered by LK SOFTWARE
Cybersecurity

AllaSenha Targets Brazilian Banks

Highlights

  • AllaSenha targets Brazilian bank accounts with a multi-stage infection chain.

  • The malware uses Azure cloud infrastructure for stealthy C2 communications.

  • AllaSenha employs advanced evasion techniques to avoid detection and persist.

Kaan Demirel
Last updated: 31 May, 2024 - 3:45 pm 3:45 pm
Kaan Demirel 12 months ago
Share
SHARE

Cybersecurity researchers have uncovered a sophisticated new variant of the AllaKore RAT, named AllaSenha, that targets Brazilian bank accounts. This malware employs a multi-stage infection process starting with phishing emails and involving malicious LNK files disguised as PDF documents. Users are deceived into downloading a harmful file, which sets off a chain of events ultimately leading to the installation of the AllaSenha malware. The malware exploits cloud services to communicate stealthily with its command-and-control (C2) server, posing a significant threat to financial security in Brazil.

Contents
Infection Chain and DeliveryAllaSenha’s Technical MechanismsInsights and Implications

Infection Chain and Delivery

AllaSenha’s infection chain begins with phishing emails that impersonate notifications for electronic invoices, urging victims to click on shortened URLs. These links redirect users to a phishing website, which tricks them into downloading a malicious file masquerading as a PDF. Upon execution, the file launches a complex series of scripts and downloads, culminating in the deployment of AllaSenha. This malware uses a domain generation algorithm to generate a list of hostnames and ports, ensuring it can evade detection by dynamically altering its communication methods.

AllaSenha leverages Microsoft Azure’s cloud infrastructure for its C2 communications. By using Azure, it masks its malicious activities under the guise of legitimate cloud services. This approach has been active since March 2024, making it a relatively recent but potent threat. The malware specifically targets browser data related to Brazilian banks, waiting until users interact with financial websites to steal credentials, two-factor authentication tokens, and QR codes.

AllaSenha’s Technical Mechanisms

The technical mechanisms of AllaSenha are intricate. A BAT file, dubbed “BPyCode Launcher,” kicks off the infection by launching a base64-encoded PowerShell script. This script downloads a Python binary and executes another encoded Python script, which then retrieves a DLL named ExecutorLoader. ExecutorLoader injects the final payload into a renamed instance of mshta.exe, ensuring stealthy execution. The malware includes a killswitch that halts its operation if it detects a Broadwell processor, demonstrating its attempt to avoid potential security environments.

AllaSenha, a new variant of the AllaKore RAT, targets Brazilian banks to steal login credentials, two-factor authentication tokens, and QR codes. It leverages the Azure cloud for C2 communication and uses a Domain Generation Algorithm (DGA) to generate unique hostnames. The malware is particularly adept at hiding its tracks, incorporating advanced techniques to avoid detection and maintain persistence on infected systems.

Insights and Implications

– AllaSenha uses well-crafted phishing emails to initiate its infection chain.
– It employs multiple scripting languages and encoded scripts to evade detection.
– The malware leverages legitimate cloud services to mask its C2 communications.

AllaSenha represents a significant evolution in the use of RATs for financial cybercrime, specifically targeting Brazilian banking users. By leveraging cloud infrastructure, it makes detection and mitigation more challenging for cybersecurity professionals. The complex multi-stage infection process and advanced evasion techniques highlight the increasing sophistication of cyber threats. The use of domain generation algorithms to create unique hostnames daily further complicates tracking and blocking efforts.

The discovery of AllaSenha underscores the importance of robust cybersecurity measures, particularly in the financial sector. Users and organizations must be vigilant against phishing attacks and ensure that their security protocols are up-to-date to defend against such sophisticated threats. Continuous monitoring and advanced threat detection solutions can help mitigate the risks posed by evolving malware like AllaSenha. This case also illustrates the need for international cooperation in cyber defense, as cybercriminals continue to exploit global cloud infrastructure to execute their attacks.

You can follow us on Youtube, Telegram, Facebook, Linkedin, Twitter ( X ), Mastodon and Bluesky

You Might Also Like

DHS Faces Scrutiny for Withholding CISA Workforce Details

MITRE’s CVE Program Faces Funding Shake-up and Future Alternatives

Microsoft Tackles 72 Vulnerabilities in May Security Update

Apple Boosts Security With Extensive Software Updates

US Authorities Dismantle Botnets and Indict Foreign Nationals

Share This Article
Facebook Twitter Copy Link Print
Kaan Demirel
By Kaan Demirel
Kaan Demirel is a 28-year-old gaming enthusiast residing in Ankara. After graduating from the Statistics department of METU, he completed his master's degree in computer science. Kaan has a particular interest in strategy and simulation games and spends his free time playing competitive games and continuously learning new things about technology and game development. He is also interested in electric vehicles and cyber security. He works as a content editor at NewsLinker, where he leverages his passion for technology and gaming.
Previous Article Hubble Captures Galactic Bar Lights
Next Article Upcoming Blackwell GPU Limited to 28GB VRAM

Stay Connected

6.2kLike
8kFollow
2.3kSubscribe
1.7kFollow

Latest News

Pushed by Tesla, Panasonic Boosts US Battery Cell Production
Electric Vehicle
Satellite Companies Advance IoT with New Innovations
IoT
Wordle Enthusiasts Crack Today’s Puzzle with Strategic Tips
Gaming
OpenAI Targets UAE for New Data Center
AI Technology
Waymo Recalls 1,200 Robotaxis Over Software Glitch
Robotics
NEWSLINKER – your premier source for the latest updates in ai, robotics, electric vehicle, gaming, and technology. We are dedicated to bringing you the most accurate, timely, and engaging content from across these dynamic industries. Join us on our journey of discovery and stay informed in this ever-evolving digital age.

ARTIFICAL INTELLIGENCE

  • Can Artificial Intelligence Achieve Consciousness?
  • What is Artificial Intelligence (AI)?
  • How does Artificial Intelligence Work?
  • Will AI Take Over the World?
  • What Is OpenAI?
  • What is Artifical General Intelligence?

ELECTRIC VEHICLE

  • What is Electric Vehicle in Simple Words?
  • How do Electric Cars Work?
  • What is the Advantage and Disadvantage of Electric Cars?
  • Is Electric Car the Future?

RESEARCH

  • Robotics Market Research & Report
  • Everything you need to know about IoT
  • What Is Wearable Technology?
  • What is FANUC Robotics?
  • What is Anthropic AI?
Technology NewsTechnology News
Follow US
About Us   -  Cookie Policy   -   Contact

© 2025 NEWSLINKER. Powered by LK SOFTWARE
Welcome Back!

Sign in to your account

Register Lost your password?