PULSE NAME
Inside agenteV2: How Brazilian Attackers Use Fake Court Summons to Steal Banking Credentials in Real Time
WHITE PetrP.73 2026-04-26 Modified: 2026-05-26
26
IOCs
MEDIUM VOLUME
The article discusses a highly sophisticated phishing campaign in Brazil leveraging a malware known as agenteV2. This interactive Banking Trojan masquerades as an official judicial summons to deceive victims into downloading a malicious payload. Once executed, the malware establishes a persistent WebSocket backdoor that allows attackers to access the victim's system in real time, enabling live financial fraud and credential theft. The threat primarily targets users in Brazil, focusing on major banks and cryptocurrency wallet extensions, thereby raising serious concerns for organizations with employees who may be exposed to the campaign.
Indicators of Compromise (4 / 26 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL YARA domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 15af977ce25de452b96affa2addb1036 2026-04-26
FileHash-MD5 285fea57345d838916153c4d8f43ab6c 2026-04-26
FileHash-MD5 826d6350724f203b911aa6c8c4626391 2026-04-26
FileHash-MD5 a48c0d5f95b1ef98f560f324fd275da1 2026-04-26