logo

In-Memory Financial Theft: Inside Banana RAT’s Operator-Driven Attacks on Brazilian Banks

ID: 865cf4d3-2350-5bac-91a5-4a653fce627f

STIX ID: report--865cf4d3-2350-5bac-91a5-4a653fce627f

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-05-25

Date Updated: 2026-05-25

Author: Ddos

...
...

TrendAI's investigation exposes "Banana RAT," a sophisticated, polymorphic banking trojan used by SHADOW-WATER-063 to execute operator-driven financial fraud against Brazilian institutions and customers. The malware uses server-side dynamic builders, fileless AES-wrapped payloads loaded via PowerShell into memory, live human-operated session hijacking (remote input, screen streaming, keylogging), and targeted Pix-QR interception to siphon funds; developers are reportedly commercializing the toolkit as MaaS, increasing scale and risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.