Banana RAT is a Windows-based Brazilian banking trojan and remote access malware family associated with fraud against Brazilian financial institutions and Pix instant-payment activity. It has been linked to the threat cluster SHADOW-WATER-063 and is used as a remote fraud platform rather than a simple downloader, combining banking-session interference with broader surveillance and endpoint control capabilities.
Observed Banana RAT campaigns use invoice-themed social engineering, especially fake NF-e electronic invoice lures, to induce execution of malicious scripts or batch files. Delivery has been reported through phishing links and WhatsApp-distributed lures. The infection chain commonly relies on hidden PowerShell staging, layered obfuscation, and in-memory decryption of later payloads. Exposed operator infrastructure showed active backend tooling capable of generating fresh, obfuscated Banana RAT variants on demand, indicating a polymorphic build pipeline designed to vary artifacts across infections while preserving core behavior.
Across analyzed branches, Banana RAT establishes persistence through scheduled tasks, including hidden tasks and variants using VBScript launchers; some samples also support Run-key fallback when elevated persistence is unavailable. Newer branches randomized installation folders and filenames per victim, while older branches used fixed Microsoft-themed naming and paths to blend into the host. Command-and-control has been observed over encrypted channels on port 443, including custom binary protocol use and newer WebSocket-based communications derived from host-specific identifiers, with reconnect logic and fallback infrastructure for resilience.
Banana RAT supports capabilities consistent with banking fraud and full remote monitoring. Reported functions include theft of banking credentials, monitoring of banking sessions, keylogging, screen capture or live screen streaming, remote input control, system and process discovery, file transfer and enumeration, and mechanisms used to facilitate Pix fraud such as QR-code interception or replacement and banking-themed overlays. These features make it suitable for real-time operator-assisted fraud during financial transactions.
The malware targets Windows systems and is focused on Brazilian victims, particularly users of major banks and localized cryptocurrency services. Its operational model, use of Portuguese-language tooling, invoice-themed lures, and emphasis on Pix-related fraud place it within the broader Brazilian banking malware ecosystem.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A newly discovered banking trojan is targeting Brazilians by disguising itself as a legitimate electronic invoice. The malware, known as Banana RAT, uses fake NF-e (Nota Fiscal Eletronica) documents to trick victims into running malicious batch files that quietly install a powerful remote access tool on their Windows systems.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
Persistence relied on a scheduled task tied to a named executable... the newer version... shifts to a VBS launcher paired with a hidden scheduled task running with system-level privileges.
ANY.RUN behavior showed: hidden PowerShell execution, base64-encoded PowerShell, task-scheduler-backed execution
ofuscador.py, which took plain PowerShell commands and rewrote them into a scrambled character sequence reassembled and run at execution time.
Sitting alongside it was a second script, ofuscador.py, which took plain PowerShell commands and rewrote them into a scrambled character sequence reassembled and run at execution time.
The earlier version... relied on fixed file names and folder paths designed to look like legitimate Windows update components. It used a lookalike domain with a spelling error...
Capability Assessment Based on payload content, sandbox behavior, and prior branch context, this branch supports: ... System and process discovery
It streams the victim’s screen live to the operator, logs every keystroke, injects fake banking overlays...
The malware connects back to its command-and-control server on port 443 using a custom binary protocol encrypted with AES-256-CBC.
Communication with attacker servers happens over an encrypted WebSocket channel, using an address built from a hashed identifier unique to each infected computer...
36 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only in related security guides, not as part of the ACR Stealer activity discussed.
Mentioned only in related security guides; described as a Brazilian banking trojan.
Banana RAT is a remote access trojan associated with Brazilian banking fraud. It targets financial activity by stealing banking credentials and interfering with payment transactions, and in this campaign it used exposed backend infrastructure to generate and obfuscate fresh payload variants on demand for evasion.
A banking-oriented remote access payload used to target Brazilian financial activity. The article describes two evolving branches with hidden PowerShell staging, persistence via Scheduled Task and Run key fallback, WebSocket C2, screen and session monitoring, remote input capability, system and process discovery, file transfer and enumeration, key input tracking, screen capture/overlay workflows, and runtime C# compilation.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.