PULSE NAME
Inside agenteV2: How Brazilian Attackers Use Fake Court Summons to Steal Banking Credentials in Real Time
WHITE PetrP.73 2026-04-26 Modified: 2026-05-26
26
IOCs
MEDIUM VOLUME
The article discusses a highly sophisticated phishing campaign in Brazil leveraging a malware known as agenteV2. This interactive Banking Trojan masquerades as an official judicial summons to deceive victims into downloading a malicious payload. Once executed, the malware establishes a persistent WebSocket backdoor that allows attackers to access the victim's system in real time, enabling live financial fraud and credential theft. The threat primarily targets users in Brazil, focusing on major banks and cryptocurrency wallet extensions, thereby raising serious concerns for organizations with employees who may be exposed to the campaign.
Indicators of Compromise (1 / 26 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL YARA domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 8a87d63110eeb782bb621b5f3154ca80bdcf5de7 2026-04-26