TF-MAL-ps1.banana_rat
📛 Threat Title
Malware family: Banana RAT
Description
ThreatFox malware family `ps1.banana_rat`. Printable name: Banana RAT.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (8)
-
web:community.gurucul.com
An investigation team mapped the full operational model of the " Banana RAT " banking trojan. Attributed to the threat cluster SHADOW-WATER-063, the malware targets Brazilian financial institutions. MDR reconstructed the entire attack chain by correlating server tooling and client payloads.
-
web:exchange.xforce.ibmcloud.com
A recent investigation by TrendAI Vision One™ Services - Managed Detection and Response (MDR) has uncovered the operational model of Banana RAT , a banking trojan targeting Brazilian financial institutions. The malware , attributed to a threat activity cluster tracked as SHADOW-WATER-063, employs sophisticated techniques such as polymorphic payload generation, staged delivery, in-memory ...
-
web:exchange.xforce.ibmcloud.com
Banana RAT is a sophisticated Windows banking remote access trojan ( RAT ) primarily targeting Brazilian financial accounts. This malware is part of a fraud operation known as SHADOW-WATER-063, which is highly localized and focuses on Brazilian banks, crypto exchanges, and the Pix payment system. Unlike typical RATs that steal credentials for later use, Banana RAT is designed for live fraud ...
-
web:otx.alienvault.com
An MDR investigation successfully mapped the complete operational infrastructure of Banana RAT , a Brazilian banking trojan operated by threat cluster SHADOW-WATER-063. The investigation uncovered both server-side and client-side components, revealing a sophisticated FastAPI-based polymorphic payload generation system that produces hash-unique builds to evade detection. The malware employs ...
-
web:socprime.com
Banana RAT is a banking trojan used by the financially motivated threat actor SHADOW-WATER-063 to steal credentials and carry out fraudulent transactions targeting Brazilian banks. The malware is delivered through a malicious batch file and relies on layered PowerShell obfuscation, in-memory execution, and AES-256 encryption to avoid detection.
-
web:vulners.com
In this blog entry, researchers from the TrendAI™ MDR team discuss how they mapped the full end-to-end operation of SHADOW-WATER-063's Banana RAT banking malware by analyzing server-side artifacts and victim-side data.
-
web:www.pcrisk.com
The malware also copies itself into a folder path that looks like a legitimate Microsoft diagnostic location, blending in with trusted system files. Combined with the in-memory execution, polymorphic builds, and AES-encrypted C&C channel, this makes Banana RAT hard to spot during a casual look at the file system or with hash-based scanners.
-
web:www.trendmicro.com
In this blog entry, researchers from the TrendAI™ MDR team discuss how they mapped the full end-to-end operation of SHADOW-WATER-063's Banana RAT banking malware by analyzing server-side artifacts and victim-side data.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.