logo

Hackers Use NF-e Invoice Lures to Deliver Banana RAT Through Malicious Batch Files

ID: 3884b242-fa14-5f1e-aaab-005fae022a8c

STIX ID: report--3884b242-fa14-5f1e-aaab-005fae022a8c

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-05-22

Date Updated: 2026-05-23

Author: Tushar Subhra Dutta

...
...

Banana RAT is a targeted and sophisticated banking RAT campaign that uses fake NF-e invoice .bat lures to install an AES-256 encrypted, in-memory payload that achieves persistence via hidden scheduled tasks. The malware—tracked as SHADOW-WATER-063/Projeto Banana—targets 16 major Brazilian banks and local crypto exchanges, provides screen streaming, keylogging, banking overlay injection, and Pix QR code interception, and uses polymorphic builds, typosquatted CDN domains, and hardened C2 infrastructure; the report includes multiple IoCs and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.