Hackers Weaponize NF-e Invoice Lures to Deploy Banana RAT
ID: 76c4a825-6924-57d4-b9a0-61132c0f89ef
STIX ID: report--76c4a825-6924-57d4-b9a0-61132c0f89ef
Feed Name: GBHackers
Researchers observed a targeted Brazilian banking-fraud campaign that abuses NF-e invoice lures and WhatsApp/phishing to deliver Banana RAT. The adversary uses a FastAPI-based payload generator to produce unique, polymorphic, AES-encrypted payloads served once per victim, enabling fileless PowerShell execution and modular .NET components for screen capture, overlays (including Pix QR manipulation), keylogging, and exfiltration; the report includes C2 domains/IPs and SHA256 IOCs and attributes the operation to a Portuguese-speaking financial threat cluster.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
