AVLay RAT Description

The AVLay RAT (Remote Access Trojan) has been spotted in campaigns targeting users located in Brazil mainly. This threat is written in the Delphi coding language. Normally, RATs have a list of capabilities which hackers take advantage of such as the ability to collect files, plant malware, access files, and processes, etc. It is interesting that the AVLay RAT's main target is any financial information that may be hosted on the compromised system.

Detects Browser Activity Regarding Banking Portals

When the AVLay RAT infects a system, its first task is to establish a connection with the C&C (Command & Control) server of the attackers. This way, the AVLay RAT can siphon information about the activity of the victim. The AVLay RAT keeps an eye for any browser activity regarding certain Brazilian banking portals. Once such activity is detected, the AVLay RAT will waste no time and contact the attackers with the information immediately.

Collects Banking Login Credentials

Once the attackers receive the notification of the AVLay RAT, they can use the keylogger of their threat to collect the login credentials of the user. However, they can instead take a screenshot of the screen or even launch a bogus overlay which would urge the user to put in the login data, and the attackers will collect it. The overlay will appear to be a legitimate page and could even ask the user for a 2FA (two-factor authentification) thus collecting additional data. The attackers have also tailored the overlay to display a bogus chat window which normally would be used to contact a bank employee for help. It is clear to see that the authors of the AVLay RAT have put in a fair bit of effort and employed a number of social engineering techniques so that they can trick the user into handing them over their banking information.

One should be vigilant when entering their banking information particularly as the AVLay RAT is not the only predator out there that targets innocent users' finance. It is crucial that you download and install a reputable anti-malware application which would keep your system and your finances safe.

Do You Suspect Your PC May Be Infected with AVLay RAT & Other Threats? Scan Your PC with SpyHunter

SpyHunter is a powerful malware remediation and protection tool designed to help provide PC users with in-depth system security analysis, detection and removal of a wide range of threats like AVLay RAT as well as a one-on-one tech support service. Download SpyHunter's FREE Malware Remover
Note: SpyHunter's scanner is only for malware detection. If SpyHunter detects malware on your PC, you will need to purchase SpyHunter's malware removal tool to remove the malware threats. Read more on SpyHunter. Free Remover allows you to run a one-off scan and receive, subject to a 48-hour waiting period, one remediation and removal. Free Remover subject to promotional details and Special Promotion Terms. To understand our policies, please also review our EULA, Privacy Policy and Threat Assessment Criteria. If you no longer wish to have SpyHunter installed on your computer, follow these steps to uninstall SpyHunter.

Security Doesn't Let You Download SpyHunter or Access the Internet?

Solutions: Your computer may have malware hiding in memory that prevents any program, including SpyHunter, from executing on your computer. Follow to download SpyHunter and gain access to the Internet:
  • Use an alternative browser. Malware may disable your browser. If you're using IE, for example, and having problems downloading SpyHunter, you should open Firefox, Chrome or Safari browser instead.
  • Use a removable media. Download SpyHunter on another clean computer, burn it to a USB flash drive, DVD/CD, or any preferred removable media, then install it on your infected computer and run SpyHunter's malware scanner.
  • Start Windows in Safe Mode. If you can not access your Window's desktop, reboot your computer in "Safe Mode with Networking" and install SpyHunter in Safe Mode.
  • IE Users: Disable proxy server for Internet Explorer to browse the web with Internet Explorer or update your anti-spyware program. Malware modifies your Windows settings to use a proxy server to prevent you from browsing the web with IE.
If you still can't install SpyHunter? View other possible causes of installation issues.

Leave a Reply

Please DO NOT use this comment system for support or billing questions. For SpyHunter technical support requests, please contact our technical support team directly by opening a customer support ticket via your SpyHunter. For billing issues, please refer to our "Billing Questions or Problems?" page. For general inquiries (complaints, legal, press, marketing, copyright), visit our "Inquiries and Feedback" page.