Threat reportMalwareTL-2026-0534

SHADOW-WATER-063 Banana RAT — Brazilian Banking Trojan with FastAPI Polymorphism Panel, AES-256-CBC PowerShell Payloads, Fileless In-Memory C# Compilation, and PIX QR Code Interception

highACTIVE

SHADOW-WATER-063 Banana RAT (TL-2026-0534), also tracked as Banana RAT, is a high-severity malware campaign, first published 2026-05-19. It is attributed to SHADOW-WATER-063 (Brazil) with medium confidence, affects Microsoft Windows, maps to 30 MITRE ATT&CK techniques (T1027, T1027.013, T1036.005), and is covered by 9 detection rules and 34 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
30MITRE ATT&CK
Actors
1SHADOW-WATER-063
Detection rules
9SPL · KQL · Sigma
IOCs
34Indicators of compromise

Key facts for TL-2026-0534

Threat ID
TL-2026-0534
Also known as
Banana RAT, Projeto Banana, Backdoor.PS1.BANANARAT.A, Trojan.PS1.BANANARAT.A
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution
SHADOW-WATER-063
Attribution confidence
MEDIUM
Nation-state nexus
Brazil
Motivation
FINANCIAL
Target sectors
financial, banking, retail-banking, fintech, individual-consumers
Target regions
Brazil, South America
Detection rules
9
Indicators of compromise
34

Malware and tooling in SHADOW-WATER-063 Banana RAT

Malware and tooling: Backdoor.PS1.BANANARAT.A, Banana RAT, Trojan.PS1.BANANARAT.A, FastAPI, ZXing.Net

How SHADOW-WATER-063 Banana RAT works

Banana RAT is a Brazilian-Portuguese-language banking trojan tracked by Trend Micro under the activity cluster SHADOW-WATER-063 (internal codename 'Projeto Banana'). The operator runs a FastAPI-based polymorphism panel that mass-produces byte-unique, AES-256-CBC-wrapped PowerShell payloads (typically 100-200 builds per delivery folder) delivered via a Consultar_NF-e.bat NF-e invoice lure distributed over WhatsApp and phishing. Once active, the implant executes fileless via IEX/[ScriptBlock]::Create, performs in-memory C# compilation through csc.exe, exposes remote screen streaming, keylogging, and HTML banking overlays for 16 Brazilian financial institutions (Itau, Bradesco, Santander, Caixa, Banco do Brasil and others), and intercepts PIX transactions by parsing QR codes with the ZXing.Net library to swap recipient keys.

Trend Micro's TrendAI MDR team published an end-to-end teardown of SHADOW-WATER-063's Banana RAT on 2026-05-19 after a four-month investigation that included direct access to the operator's exposed build server at 24.199.90.58. The operation is a clear next-generation evolution of the 'Tetrade' family of Brazilian banking trojans (Grandoreiro, Mekotio, Casbaneiro, Guildma, CHAVECLOAK) but introduces three notable tradecraft innovations: industrial-scale per-victim polymorphism, fileless PowerShell-only execution, and PIX-aware overlay logic.

The build server runs a FastAPI application (servidor_completo_pool.py, monitor_pool.py) backed by a worker pool that pre-generates batches of 100-200 PowerShell payloads per affiliate folder. Each build is byte-unique: the loader stub is randomized (variable names, comment noise, junk operations) and the inner stage is encrypted with AES-256-CBC using a freshly generated key/IV pair embedded in the dropper. A stats-view.php dashboard tracks per-affiliate distribution counts and successful infections, mirroring the Mekotio operator workflow but at greater scale.

Initial access begins with a phishing message — usually delivered via WhatsApp, but also via email — claiming the recipient has an outstanding nota fiscal eletronica (NF-e) invoice. The lure attaches Consultar_NF-e.bat, a small CMD wrapper that pulls the encrypted PowerShell loader (st.txt, st.php, payload.php) from one of the operator-controlled domains (convitemundial2026[.]com, c[.]windowsk-cdn[.]com, windowsk-cdn[.]com). The .bat invokes powershell.exe with -ExecutionPolicy Bypass -WindowStyle Hidden and pipes the downloaded ciphertext into a decryptor that calls [ScriptBlock]::Create on the decrypted plaintext and pipes the result through IEX. No PowerShell script ever lands on disk; the only on-disk artifacts are the .bat, two staged blobs in C:\Users\Public\Documents\msedge.txt and C:\Users\<user>\AppData\Roaming\Microsoft\Diagnosis\ETW\msedgeupdate.txt (used as a configuration cache), and the csc.exe-compiled in-memory module written to %TEMP%.

The second stage is a PowerShell-orchestrated C# loader. Banana RAT writes a C# source string to memory, invokes csc.exe via System.CodeDom.Compiler.CodeDomProvider to compile it into a transient .dll, then reflectively loads it via [System.Reflection.Assembly]::Load. The compiled assembly hosts the actual RAT functionality, intentionally splitting the kill chain across PowerShell -> csc.exe -> .NET reflection to defeat static AMSI/AV signatures on the .NET implant itself. The loader also drops persistence: an HKCU\Software\Microsoft\Windows\CurrentVersion\Run value pointing back to the .bat staging file, and a scheduled task named 'MicrosoftEdgeUpdateTaskMachineUA' for redundancy.

Once running, the implant beacons over HTTPS (443/tcp) and HTTP (80/tcp) to the C&C, registering itself with a victim ID derived from MAC + username + hostname. The C&C protocol is JSON over POST with AES-256-CBC body encryption, the same key family as the dropper. Commands supported include: screen_stream (MJPEG-style frame push for live RDP-style viewing), keylog_dump, overlay_open (loads one of 16 HTML banking overlays from the embedded resource pool), pix_intercept (monitors clipboard and any open windows for PIX QR codes, decodes them with ZXing.Net, swaps the destination key with an operator-controlled key, and re-encodes), browser_cookie_steal, and reverse_proxy.

The PIX interception module is the most operationally novel component. PIX is Brazil's instant-payment system, and QR codes are the dominant point-of-sale and peer-to-peer flow. Banana RAT continuously scans clipboard contents and visible window bitmaps (via PrintWindow GDI calls) for content matching the PIX BR Code payload format (starts with '00020126'). When a match is found, the ZXing.Net decoder extracts the merchant PIX key, the operator substitutes their own attacker-controlled PIX key, the EMV-style CRC16 is recomputed, and the modified QR is re-rendered and replaced in the clipboard or pasted back into the bank window. The victim then completes the payment to the attacker's account believing they are paying the legitimate merchant.

The overlay subsystem targets sixteen Brazilian institutions including Itau Unibanco, Bradesco, Santander Brasil, Caixa Economica Federal, Banco do Brasil, BTG Pactual, Nubank, Inter, C6 Bank, Sicoob, Sicredi, Banrisul, Original, Safra, Pan, and Mercado Pago. Each overlay is a HTML/JS page rendered in a borderless WebView2 window pinned over the legitimate banking application's login screen, harvesting credentials, transaction passwords, and 2FA OTPs in real time, then relaying them to the C&C for live-fraud operation.

Trend Micro coordinated disclosure with FEBRABAN (Brazilian Federation of Banks) given the regulator-level impact. At the time of publication, the primary C&C node 24.199.90.58 (a DigitalOcean droplet) remained publicly accessible with the build server exposed, and 162.141.111.227 was operating as a secondary fallback. The Trend Micro detections Backdoor.PS1.BANANARAT.A and Trojan.PS1.BANANARAT.A are deployed across their global telemetry.

Attribution to a Brazilian operator is moderate-confidence: Portuguese-language source comments, Brazilian timezone (BRT) build timestamps, exclusive targeting of Brazilian banks, PIX-specific functionality, and code-pattern overlap with Mekotio and Grandoreiro overlays. The 'Projeto Banana' codename appears in operator logs on the exposed server.

MITRE ATT&CK techniques used in TL-2026-0534

Defense Evasion

T1027 Obfuscated Files or Information; T1027.013 Obfuscated Files or Information: Encrypted/Encoded File; T1036.005 Match Legitimate Resource Name or Location; T1127 Trusted Developer Utilities Proxy Execution; T1620 Reflective Code Loading

Exfiltration

T1041 Exfiltration Over C2 Channel

Persistence

T1053.005 Scheduled Task/Job: Scheduled Task; T1547.001 Registry Run Keys / Startup Folder

Collection

T1056 Input Capture; T1113 Screen Capture; T1115 Clipboard Data

Credential Access

T1056.001 Input Capture: Keylogging; T1056.002 Input Capture: GUI Input Capture; T1555.003 Credentials from Password Stores: Credentials from Web Browsers

Discovery

T1057 Process Discovery; T1082 System Information Discovery

Execution

T1059.001 Command and Scripting Interpreter: PowerShell; T1059.003 Command and Scripting Interpreter: Windows Command Shell; T1106 Native API; T1204.002 User Execution: Malicious File

Command and Control

T1071.001 Application Layer Protocol: Web Protocols; T1090 Proxy; T1105 Ingress Tool Transfer; T1573.001 Encrypted Channel: Symmetric Cryptography

Impact

T1565.002 Transmitted Data Manipulation; T1657 Financial Theft

Initial Access

T1566 Phishing; T1566.001 Phishing: Spearphishing Attachment; T1566.003 Phishing: Spearphishing via Service

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in SHADOW-WATER-063 Banana RAT

  • Microsoft — Windows
    Vulnerable versions: 10; 11; Server 2019; Server 2022
  • Itau Unibanco — Internet Banking + Mobile App
    Vulnerable versions: all
  • Bradesco — Internet Banking + Mobile App
    Vulnerable versions: all
  • Santander Brasil — Internet Banking + Mobile App
    Vulnerable versions: all
  • Caixa Economica Federal — Internet Banking + Mobile App
    Vulnerable versions: all
  • Banco do Brasil — Internet Banking + Mobile App
    Vulnerable versions: all
  • Nubank — Mobile App + Web
    Vulnerable versions: all
  • Banco Central do Brasil — PIX instant payment system (BR Code QR)
    Vulnerable versions: all

Remediation for SHADOW-WATER-063 Banana RAT

Immediate actions

  • Block all listed C2 domains (convitemundial2026.com, c.windowsk-cdn.com, windowsk-cdn.com) at DNS and web proxy
  • Block C2 IPs 24.199.90.58 and 162.141.111.227 at perimeter and EDR network policy
  • Hunt for Consultar_NF-e.bat and any *NF-e*.bat artifacts in mail gateways, EDR file inventories, and SMB shares
  • Hunt for the staging paths C:\Users\Public\Documents\msedge.txt and %APPDATA%\Microsoft\Diagnosis\ETW\msedgeupdate.txt on Windows endpoints
  • Disable WhatsApp Desktop attachment auto-save on corporate endpoints where business policy allows
  • Notify Brazilian fraud-operations teams to monitor for atypical PIX outflows to unknown destination keys

Workarounds

  • If PowerShell is not required for end users, set Constrained Language Mode via AppLocker policy
  • Block .bat execution from email attachments and WhatsApp Desktop downloads via Group Policy

Longer-term hardening

  • Deploy AMSI-enabled EDR with PowerShell ScriptBlock logging (Event ID 4104) at Verbose level
  • Enable Windows Defender Attack Surface Reduction rule 'Block execution of potentially obfuscated scripts' (D3E037E1-3EB8-44C8-A917-57927947596D)
  • Restrict csc.exe (and the .NET Framework C# compiler under %WINDIR%\Microsoft.NET\Framework*) via WDAC or AppLocker on user endpoints — legitimate developer workstations should be exempted
  • Block child-process creation by powershell.exe spawning csc.exe via EDR or Defender ASR equivalents
  • Deploy banking-malware-aware browser-isolation or remote-browser policy for retail banking sessions on shared endpoints
  • Customer education on NF-e phishing lures over WhatsApp and email

Weaknesses (CWE) in SHADOW-WATER-063 Banana RAT

CWE-506, CWE-94, CWE-78, CWE-829

Timeline of SHADOW-WATER-063 Banana RAT

  • Trend Micro TrendAI MDR first observes Consultar_NF-e.bat phishing wave targeting Brazilian retail-banking customers via WhatsApp.
  • Investigators identify the publicly accessible FastAPI build server at 24.199.90.58 hosting servidor_completo_pool.py, monitor_pool.py, and stats-view.php.
  • Polymorphism panel reverse engineered: 100-200 byte-unique AES-256-CBC builds per affiliate folder confirmed.
  • Live PIX QR-code interception observed in MDR telemetry — ZXing.Net-based decoder and re-encoder identified inside the in-memory C# stage.
  • Fallback C2 162.141.111.227 mapped via beacon failover during operator infrastructure rotation.
  • Trend Micro initiates coordinated disclosure with FEBRABAN and impacted Brazilian financial institutions.
  • Threadlinqs Intelligence publishes TL-2026-0534 covering Banana RAT IOCs, MITRE mapping, simulations, and detections.
  • Trend Micro publishes full SHADOW-WATER-063 Banana RAT teardown; Backdoor.PS1.BANANARAT.A and Trojan.PS1.BANANARAT.A signatures shipped globally.
  • As of 2026-05-29, Banana RAT (SHADOW-WATER-063) remains an active Brazilian banking-trojan campaign: disclosed by Trend Micro on 2026-05-19 with C2 (24.199.90.58, DigitalOcean) still live and fallback operating, no takedown, sinkhole, or arrests reported. Multiple vendors corroborate it as an ongoing, credible PIX-fraud threat; no CVE, so phishing/LOLBAS TTPs stay fully viable.

Sources cited for SHADOW-WATER-063 Banana RAT

Detection coverage for TL-2026-0534

As of 2026-05-19, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0534 across Splunk SPL, Microsoft KQL and Sigma, covering 34 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
34 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats