s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-ps1.banana_rat

📛 Threat Title

Malware family: Banana RAT

Category: Banana RAT First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `ps1.banana_rat`. Printable name: Banana RAT.

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (8)

  • web:community.gurucul.com

    An investigation team mapped the full operational model of the " Banana RAT " banking trojan. Attributed to the threat cluster SHADOW-WATER-063, the malware targets Brazilian financial institutions. MDR reconstructed the entire attack chain by correlating server tooling and client payloads.

  • web:exchange.xforce.ibmcloud.com

    A recent investigation by TrendAI Vision One™ Services - Managed Detection and Response (MDR) has uncovered the operational model of Banana RAT , a banking trojan targeting Brazilian financial institutions. The malware , attributed to a threat activity cluster tracked as SHADOW-WATER-063, employs sophisticated techniques such as polymorphic payload generation, staged delivery, in-memory ...

  • web:exchange.xforce.ibmcloud.com

    Banana RAT is a sophisticated Windows banking remote access trojan ( RAT ) primarily targeting Brazilian financial accounts. This malware is part of a fraud operation known as SHADOW-WATER-063, which is highly localized and focuses on Brazilian banks, crypto exchanges, and the Pix payment system. Unlike typical RATs that steal credentials for later use, Banana RAT is designed for live fraud ...

  • web:otx.alienvault.com

    An MDR investigation successfully mapped the complete operational infrastructure of Banana RAT , a Brazilian banking trojan operated by threat cluster SHADOW-WATER-063. The investigation uncovered both server-side and client-side components, revealing a sophisticated FastAPI-based polymorphic payload generation system that produces hash-unique builds to evade detection. The malware employs ...

  • web:socprime.com

    Banana RAT is a banking trojan used by the financially motivated threat actor SHADOW-WATER-063 to steal credentials and carry out fraudulent transactions targeting Brazilian banks. The malware is delivered through a malicious batch file and relies on layered PowerShell obfuscation, in-memory execution, and AES-256 encryption to avoid detection.

  • web:vulners.com

    In this blog entry, researchers from the TrendAI™ MDR team discuss how they mapped the full end-to-end operation of SHADOW-WATER-063's Banana RAT banking malware by analyzing server-side artifacts and victim-side data.

  • web:www.pcrisk.com

    The malware also copies itself into a folder path that looks like a legitimate Microsoft diagnostic location, blending in with trusted system files. Combined with the in-memory execution, polymorphic builds, and AES-encrypted C&C channel, this makes Banana RAT hard to spot during a casual look at the file system or with hash-based scanners.

  • web:www.trendmicro.com

    In this blog entry, researchers from the TrendAI™ MDR team discuss how they mapped the full end-to-end operation of SHADOW-WATER-063's Banana RAT banking malware by analyzing server-side artifacts and victim-side data.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.