logo

Peeling back Banana RAT.

ID: f22f325c-2b0b-584c-9f90-739153f2beef

STIX ID: report--f22f325c-2b0b-584c-9f90-739153f2beef

Feed Name: The CyberWire

Threat Score
75/100

Date Published: 2026-06-20

Date Updated: 2026-06-20

...
...

Trend Micro MDR uncovered the full operation behind Banana RAT (SHADOW-WATER-063), a sophisticated banking trojan targeting Brazilian banks that uses fileless PowerShell, layered obfuscation, and remote-control functionality to steal credentials, manipulate sessions, and intercept Pix QR payments; the campaign appears operated by a Brazilian Portuguese-speaking group linked to the Tetrade ecosystem and may be shifting toward a malware-as-a-service model.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.