PULSE NAME
Inside Banana RAT: From Build Server to Banking Fraud
WHITE SHADOW-WATER-063 AlienVault 2026-05-19 Modified: 2026-05-21
11
IOCs
MEDIUM VOLUME
An MDR investigation successfully mapped the complete operational infrastructure of Banana RAT, a Brazilian banking trojan operated by threat cluster SHADOW-WATER-063. The investigation uncovered both server-side and client-side components, revealing a sophisticated FastAPI-based polymorphic payload generation system that produces hash-unique builds to evade detection. The malware employs layered obfuscation, AES-wrapped payloads, and fileless PowerShell execution. Once deployed, it enables operator-driven fraud through remote input control, keylogging, screen streaming, bank-branded overlays, and Pix QR code interception specifically targeting Brazilian financial institutions. The tooling exclusively targets 16 Brazilian banks and crypto exchanges, with all operator artifacts written in Brazilian Portuguese, indicating a financially motivated actor operating within the Tetrade banking trojan ecosystem.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Banana RAT Grandoreiro - S0531 Mekotio Metamorfo - S0455 Casbaneiro Astaroth - S0373 Guildma CHAVECLOAK
Indicators of Compromise (11)
All FileHash-SHA256 IPv4 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 38dfeb772afbd01c04eddda120d283acfb1147a6dc3d54ac62fe23ad06e39d8f 2026-05-19
FileHash-SHA256 4912b1134e69ade7266e8508eec33ccb2d80ad693f1dbc4f1f4344c6dfcf2ff1 2026-05-19
FileHash-SHA256 d7545b6dacebdae27effb3c778c5e349027ec789c76ae4f777bd9ba56a70cdaa 2026-05-19
FileHash-SHA256 ecdc8fade561a75d68235859ad8b1fe131db2c458b4894268e38e90ecab1c47f 2026-05-19
IPv4 162.141.111.227 2026-05-19
URL http://24.199.90.58/payload.php 2026-05-19
URL http://24.199.90.58:80/payload.php 2026-05-19
URL https://convitemundial2026.com/Consultar_NF-e.bat 2026-05-19
domain convitemundial2026.com 2026-05-19
domain windowsk-cdn.com 2026-05-19
hostname c.windowsk-cdn.com 2026-05-19