← Back to Pulse Feed
PULSE DETAIL
An MDR investigation successfully mapped the complete operational infrastructure of Banana RAT, a Brazilian banking trojan operated by threat cluster SHADOW-WATER-063. The investigation uncovered both server-side and client-side components, revealing a sophisticated FastAPI-based polymorphic payload generation system that produces hash-unique builds to evade detection. The malware employs layered obfuscation, AES-wrapped payloads, and fileless PowerShell execution. Once deployed, it enables operator-driven fraud through remote input control, keylogging, screen streaming, bank-branded overlays, and Pix QR code interception specifically targeting Brazilian financial institutions. The tooling exclusively targets 16 Brazilian banks and crypto exchanges, with all operator artifacts written in Brazilian Portuguese, indicating a financially motivated actor operating within the Tetrade banking trojan ecosystem.
MITRE ATT&CK & Malware Families
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-SHA256 | 38dfeb772afbd01c04eddda120d283acfb1147a6dc3d54ac62fe23ad06e39d8f | — | 2026-05-19 | |
| FileHash-SHA256 | 4912b1134e69ade7266e8508eec33ccb2d80ad693f1dbc4f1f4344c6dfcf2ff1 | — | 2026-05-19 | |
| FileHash-SHA256 | d7545b6dacebdae27effb3c778c5e349027ec789c76ae4f777bd9ba56a70cdaa | — | 2026-05-19 | |
| FileHash-SHA256 | ecdc8fade561a75d68235859ad8b1fe131db2c458b4894268e38e90ecab1c47f | — | 2026-05-19 | |
| IPv4 | 162.141.111.227 | — | 2026-05-19 | |
| URL | http://24.199.90.58/payload.php | — | 2026-05-19 | |
| URL | http://24.199.90.58:80/payload.php | — | 2026-05-19 | |
| URL | https://convitemundial2026.com/Consultar_NF-e.bat | — | 2026-05-19 | |
| domain | convitemundial2026.com | — | 2026-05-19 | |
| domain | windowsk-cdn.com | — | 2026-05-19 | |
| hostname | c.windowsk-cdn.com | — | 2026-05-19 |