Threat reportMalwareTL-2026-0534
SHADOW-WATER-063 Banana RAT — Brazilian Banking Trojan with FastAPI Polymorphism Panel, AES-256-CBC PowerShell Payloads, Fileless In-Memory C# Compilation, and PIX QR Code Interception
SHADOW-WATER-063 Banana RAT (TL-2026-0534), also tracked as Banana RAT, is a high-severity malware campaign, first published 2026-05-19. It is attributed to SHADOW-WATER-063 (Brazil) with medium confidence, affects Microsoft Windows, maps to 30 MITRE ATT&CK techniques (T1027, T1027.013, T1036.005), and is covered by 9 detection rules and 34 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 30MITRE ATT&CK
- Actors
- 1SHADOW-WATER-063
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 34Indicators of compromise
Key facts for TL-2026-0534
- Threat ID
- TL-2026-0534
- Also known as
- Banana RAT, Projeto Banana, Backdoor.PS1.BANANARAT.A, Trojan.PS1.BANANARAT.A
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution
- SHADOW-WATER-063
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Brazil
- Motivation
- FINANCIAL
- Target sectors
- financial, banking, retail-banking, fintech, individual-consumers
- Target regions
- Brazil, South America
- Detection rules
- 9
- Indicators of compromise
- 34
Malware and tooling in SHADOW-WATER-063 Banana RAT
Malware and tooling: Backdoor.PS1.BANANARAT.A, Banana RAT, Trojan.PS1.BANANARAT.A, FastAPI, ZXing.Net
How SHADOW-WATER-063 Banana RAT works
Banana RAT is a Brazilian-Portuguese-language banking trojan tracked by Trend Micro under the activity cluster SHADOW-WATER-063 (internal codename 'Projeto Banana'). The operator runs a FastAPI-based polymorphism panel that mass-produces byte-unique, AES-256-CBC-wrapped PowerShell payloads (typically 100-200 builds per delivery folder) delivered via a Consultar_NF-e.bat NF-e invoice lure distributed over WhatsApp and phishing. Once active, the implant executes fileless via IEX/[ScriptBlock]::Create, performs in-memory C# compilation through csc.exe, exposes remote screen streaming, keylogging, and HTML banking overlays for 16 Brazilian financial institutions (Itau, Bradesco, Santander, Caixa, Banco do Brasil and others), and intercepts PIX transactions by parsing QR codes with the ZXing.Net library to swap recipient keys.
Trend Micro's TrendAI MDR team published an end-to-end teardown of SHADOW-WATER-063's Banana RAT on 2026-05-19 after a four-month investigation that included direct access to the operator's exposed build server at 24.199.90.58. The operation is a clear next-generation evolution of the 'Tetrade' family of Brazilian banking trojans (Grandoreiro, Mekotio, Casbaneiro, Guildma, CHAVECLOAK) but introduces three notable tradecraft innovations: industrial-scale per-victim polymorphism, fileless PowerShell-only execution, and PIX-aware overlay logic.
The build server runs a FastAPI application (servidor_completo_pool.py, monitor_pool.py) backed by a worker pool that pre-generates batches of 100-200 PowerShell payloads per affiliate folder. Each build is byte-unique: the loader stub is randomized (variable names, comment noise, junk operations) and the inner stage is encrypted with AES-256-CBC using a freshly generated key/IV pair embedded in the dropper. A stats-view.php dashboard tracks per-affiliate distribution counts and successful infections, mirroring the Mekotio operator workflow but at greater scale.
Initial access begins with a phishing message — usually delivered via WhatsApp, but also via email — claiming the recipient has an outstanding nota fiscal eletronica (NF-e) invoice. The lure attaches Consultar_NF-e.bat, a small CMD wrapper that pulls the encrypted PowerShell loader (st.txt, st.php, payload.php) from one of the operator-controlled domains (convitemundial2026[.]com, c[.]windowsk-cdn[.]com, windowsk-cdn[.]com). The .bat invokes powershell.exe with -ExecutionPolicy Bypass -WindowStyle Hidden and pipes the downloaded ciphertext into a decryptor that calls [ScriptBlock]::Create on the decrypted plaintext and pipes the result through IEX. No PowerShell script ever lands on disk; the only on-disk artifacts are the .bat, two staged blobs in C:\Users\Public\Documents\msedge.txt and C:\Users\<user>\AppData\Roaming\Microsoft\Diagnosis\ETW\msedgeupdate.txt (used as a configuration cache), and the csc.exe-compiled in-memory module written to %TEMP%.
The second stage is a PowerShell-orchestrated C# loader. Banana RAT writes a C# source string to memory, invokes csc.exe via System.CodeDom.Compiler.CodeDomProvider to compile it into a transient .dll, then reflectively loads it via [System.Reflection.Assembly]::Load. The compiled assembly hosts the actual RAT functionality, intentionally splitting the kill chain across PowerShell -> csc.exe -> .NET reflection to defeat static AMSI/AV signatures on the .NET implant itself. The loader also drops persistence: an HKCU\Software\Microsoft\Windows\CurrentVersion\Run value pointing back to the .bat staging file, and a scheduled task named 'MicrosoftEdgeUpdateTaskMachineUA' for redundancy.
Once running, the implant beacons over HTTPS (443/tcp) and HTTP (80/tcp) to the C&C, registering itself with a victim ID derived from MAC + username + hostname. The C&C protocol is JSON over POST with AES-256-CBC body encryption, the same key family as the dropper. Commands supported include: screen_stream (MJPEG-style frame push for live RDP-style viewing), keylog_dump, overlay_open (loads one of 16 HTML banking overlays from the embedded resource pool), pix_intercept (monitors clipboard and any open windows for PIX QR codes, decodes them with ZXing.Net, swaps the destination key with an operator-controlled key, and re-encodes), browser_cookie_steal, and reverse_proxy.
The PIX interception module is the most operationally novel component. PIX is Brazil's instant-payment system, and QR codes are the dominant point-of-sale and peer-to-peer flow. Banana RAT continuously scans clipboard contents and visible window bitmaps (via PrintWindow GDI calls) for content matching the PIX BR Code payload format (starts with '00020126'). When a match is found, the ZXing.Net decoder extracts the merchant PIX key, the operator substitutes their own attacker-controlled PIX key, the EMV-style CRC16 is recomputed, and the modified QR is re-rendered and replaced in the clipboard or pasted back into the bank window. The victim then completes the payment to the attacker's account believing they are paying the legitimate merchant.
The overlay subsystem targets sixteen Brazilian institutions including Itau Unibanco, Bradesco, Santander Brasil, Caixa Economica Federal, Banco do Brasil, BTG Pactual, Nubank, Inter, C6 Bank, Sicoob, Sicredi, Banrisul, Original, Safra, Pan, and Mercado Pago. Each overlay is a HTML/JS page rendered in a borderless WebView2 window pinned over the legitimate banking application's login screen, harvesting credentials, transaction passwords, and 2FA OTPs in real time, then relaying them to the C&C for live-fraud operation.
Trend Micro coordinated disclosure with FEBRABAN (Brazilian Federation of Banks) given the regulator-level impact. At the time of publication, the primary C&C node 24.199.90.58 (a DigitalOcean droplet) remained publicly accessible with the build server exposed, and 162.141.111.227 was operating as a secondary fallback. The Trend Micro detections Backdoor.PS1.BANANARAT.A and Trojan.PS1.BANANARAT.A are deployed across their global telemetry.
Attribution to a Brazilian operator is moderate-confidence: Portuguese-language source comments, Brazilian timezone (BRT) build timestamps, exclusive targeting of Brazilian banks, PIX-specific functionality, and code-pattern overlap with Mekotio and Grandoreiro overlays. The 'Projeto Banana' codename appears in operator logs on the exposed server.
MITRE ATT&CK techniques used in TL-2026-0534
Defense Evasion
T1027 Obfuscated Files or Information; T1027.013 Obfuscated Files or Information: Encrypted/Encoded File; T1036.005 Match Legitimate Resource Name or Location; T1127 Trusted Developer Utilities Proxy Execution; T1620 Reflective Code Loading
Exfiltration
T1041 Exfiltration Over C2 Channel
Persistence
T1053.005 Scheduled Task/Job: Scheduled Task; T1547.001 Registry Run Keys / Startup Folder
Collection
T1056 Input Capture; T1113 Screen Capture; T1115 Clipboard Data
Credential Access
T1056.001 Input Capture: Keylogging; T1056.002 Input Capture: GUI Input Capture; T1555.003 Credentials from Password Stores: Credentials from Web Browsers
Discovery
T1057 Process Discovery; T1082 System Information Discovery
Execution
T1059.001 Command and Scripting Interpreter: PowerShell; T1059.003 Command and Scripting Interpreter: Windows Command Shell; T1106 Native API; T1204.002 User Execution: Malicious File
Command and Control
T1071.001 Application Layer Protocol: Web Protocols; T1090 Proxy; T1105 Ingress Tool Transfer; T1573.001 Encrypted Channel: Symmetric Cryptography
Impact
T1565.002 Transmitted Data Manipulation; T1657 Financial Theft
Initial Access
T1566 Phishing; T1566.001 Phishing: Spearphishing Attachment; T1566.003 Phishing: Spearphishing via Service
defense-impairment
Affected products and versions in SHADOW-WATER-063 Banana RAT
- Microsoft — Windows
Vulnerable versions: 10; 11; Server 2019; Server 2022 - Itau Unibanco — Internet Banking + Mobile App
Vulnerable versions: all - Bradesco — Internet Banking + Mobile App
Vulnerable versions: all - Santander Brasil — Internet Banking + Mobile App
Vulnerable versions: all - Caixa Economica Federal — Internet Banking + Mobile App
Vulnerable versions: all - Banco do Brasil — Internet Banking + Mobile App
Vulnerable versions: all - Nubank — Mobile App + Web
Vulnerable versions: all - Banco Central do Brasil — PIX instant payment system (BR Code QR)
Vulnerable versions: all
Remediation for SHADOW-WATER-063 Banana RAT
Immediate actions
- Block all listed C2 domains (convitemundial2026.com, c.windowsk-cdn.com, windowsk-cdn.com) at DNS and web proxy
- Block C2 IPs 24.199.90.58 and 162.141.111.227 at perimeter and EDR network policy
- Hunt for Consultar_NF-e.bat and any *NF-e*.bat artifacts in mail gateways, EDR file inventories, and SMB shares
- Hunt for the staging paths C:\Users\Public\Documents\msedge.txt and %APPDATA%\Microsoft\Diagnosis\ETW\msedgeupdate.txt on Windows endpoints
- Disable WhatsApp Desktop attachment auto-save on corporate endpoints where business policy allows
- Notify Brazilian fraud-operations teams to monitor for atypical PIX outflows to unknown destination keys
Workarounds
- If PowerShell is not required for end users, set Constrained Language Mode via AppLocker policy
- Block .bat execution from email attachments and WhatsApp Desktop downloads via Group Policy
Longer-term hardening
- Deploy AMSI-enabled EDR with PowerShell ScriptBlock logging (Event ID 4104) at Verbose level
- Enable Windows Defender Attack Surface Reduction rule 'Block execution of potentially obfuscated scripts' (D3E037E1-3EB8-44C8-A917-57927947596D)
- Restrict csc.exe (and the .NET Framework C# compiler under %WINDIR%\Microsoft.NET\Framework*) via WDAC or AppLocker on user endpoints — legitimate developer workstations should be exempted
- Block child-process creation by powershell.exe spawning csc.exe via EDR or Defender ASR equivalents
- Deploy banking-malware-aware browser-isolation or remote-browser policy for retail banking sessions on shared endpoints
- Customer education on NF-e phishing lures over WhatsApp and email
Weaknesses (CWE) in SHADOW-WATER-063 Banana RAT
Timeline of SHADOW-WATER-063 Banana RAT
- Trend Micro TrendAI MDR first observes Consultar_NF-e.bat phishing wave targeting Brazilian retail-banking customers via WhatsApp.
- Investigators identify the publicly accessible FastAPI build server at 24.199.90.58 hosting servidor_completo_pool.py, monitor_pool.py, and stats-view.php.
- Polymorphism panel reverse engineered: 100-200 byte-unique AES-256-CBC builds per affiliate folder confirmed.
- Live PIX QR-code interception observed in MDR telemetry — ZXing.Net-based decoder and re-encoder identified inside the in-memory C# stage.
- Fallback C2 162.141.111.227 mapped via beacon failover during operator infrastructure rotation.
- Trend Micro initiates coordinated disclosure with FEBRABAN and impacted Brazilian financial institutions.
- Threadlinqs Intelligence publishes TL-2026-0534 covering Banana RAT IOCs, MITRE mapping, simulations, and detections.
- Trend Micro publishes full SHADOW-WATER-063 Banana RAT teardown; Backdoor.PS1.BANANARAT.A and Trojan.PS1.BANANARAT.A signatures shipped globally.
- As of 2026-05-29, Banana RAT (SHADOW-WATER-063) remains an active Brazilian banking-trojan campaign: disclosed by Trend Micro on 2026-05-19 with C2 (24.199.90.58, DigitalOcean) still live and fallback operating, no takedown, sinkhole, or arrests reported. Multiple vendors corroborate it as an ongoing, credible PIX-fraud threat; no CVE, so phishing/LOLBAS TTPs stay fully viable.
Sources cited for SHADOW-WATER-063 Banana RAT
- Inside SHADOW-WATER-063 Banana RAT: From Build Server to Banking Fraud
- Tetrade Family Background — Kaspersky on Brazilian Banking Trojans (Grandoreiro/Mekotio/Casbaneiro/Guildma)
- Banco Central do Brasil — PIX Manual de Iniciacao do Recebedor (BR Code spec)
- FEBRABAN Coordinated Disclosure Bulletin — Banana RAT
- MITRE ATT&CK T1059.001 PowerShell
- MITRE ATT&CK T1127.001 InstallUtil/csc.exe Trusted Developer Utility
- ZXing.Net QR Decoding Library
- CHAVECLOAK Brazilian Banker Analysis
Detection coverage for TL-2026-0534
As of 2026-05-19, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0534 across Splunk SPL, Microsoft KQL and Sigma, covering 34 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.