Zumanek is a malware categorized as a banking Remote Access Trojan (RAT). It was distributed in October 2020 targeting Latin American banking customers.
This malware is distributed through social engineering. In this, cybercriminals use phishing tactics to trick users into downloading and installing Zumanek in their systems without their consent. The primary purpose of Zumanek is to steal bank accounts and crypto wallet credentials.
Currently, the trojan has targeted users mainly in Brazil. Also, dropper (the ‘executable’ which downloads Zumanek) checks the system’s geolocation, and if it is not Brazil, the trojan is not downloaded. Since the motivation of the cybercriminals is purely financial, the hijacked bank accounts and crypto wallets are likely misused for fraudulent online purchases, account transfers, etc. Thus, this infection might lead to significant financial loss to the users.