# SHADOW-WATER-063 Banana RAT — Brazilian Banking Trojan with FastAPI Polymorphism Panel, AES-256-CBC PowerShell Payloads, Fileless In-Memory C# Compilation, and PIX QR Code Interception

> Banana RAT is a Brazilian-Portuguese-language banking trojan tracked by Trend Micro under the activity cluster SHADOW-WATER-063 (internal codename 'Projeto Banana'). The operator runs a FastAPI-based polymorphism panel that mass-produces byte-unique, AES-256-CBC-wrapped PowerShell payloads (typically 100-200 builds per delivery folder) delivered via a Consultar_NF-e.bat NF-e invoice lure distributed over WhatsApp and phishing. Once active, the implant executes fileless via IEX/[ScriptBlock]::Create, performs in-memory C# compilation through csc.exe, exposes remote screen streaming, keylogging, and HTML banking overlays for 16 Brazilian financial institutions (Itau, Bradesco, Santander, Caixa, Banco do Brasil and others), and intercepts PIX transactions by parsing QR codes with the ZXing.Net library to swap recipient keys.

- **Published:** 2026-05-19T12:00:00Z
- **Last reviewed:** 2026-05-19T12:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0534
- **ID:** TL-2026-0534
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Actor:** SHADOW-WATER-063 (Brazil)
- **Detections:** 9 · **IOCs:** 34 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Trend Micro's TrendAI MDR team published an end-to-end teardown of SHADOW-WATER-063's Banana RAT on 2026-05-19 after a four-month investigation that included direct access to the operator's exposed build server at 24.199.90.58. The operation is a clear next-generation evolution of the 'Tetrade' family of Brazilian banking trojans (Grandoreiro, Mekotio, Casbaneiro, Guildma, CHAVECLOAK) but introduces three notable tradecraft innovations: industrial-scale per-victim polymorphism, fileless PowerShell-only execution, and PIX-aware overlay logic.

The build server runs a FastAPI application (servidor_completo_pool.py, monitor_pool.py) backed by a worker pool that pre-generates batches of 100-200 PowerShell payloads per affiliate folder. Each build is byte-unique: the loader stub is randomized (variable names, comment noise, junk operations) and the inner stage is encrypted with AES-256-CBC using a freshly generated key/IV pair embedded in the dropper. A stats-view.php dashboard tracks per-affiliate distribution counts and successful infections, mirroring the Mekotio operator workflow but at greater scale.

Initial access begins with a phishing message — usually delivered via WhatsApp, but also via email — claiming the recipient has an outstanding nota fiscal eletronica (NF-e) invoice. The lure attaches Consultar_NF-e.bat, a small CMD wrapper that pulls the encrypted PowerShell loader (st.txt, st.php, payload.php) from one of the operator-controlled domains (convitemundial2026[.]com, c[.]windowsk-cdn[.]com, windowsk-cdn[.]com). The .bat invokes powershell.exe with -ExecutionPolicy Bypass -WindowStyle Hidden and pipes the downloaded ciphertext into a decryptor that calls [ScriptBlock]::Create on the decrypted plaintext and pipes the result through IEX. No PowerShell script ever lands on disk; the only on-disk artifacts are the .bat, two staged blobs in C:\Users\Public\Documents\msedge.txt and C:\Users\<user>\AppData\Roaming\Microsoft\Diagnosis\ETW\msedgeupdate.txt (used as a configuration cache), and the csc.exe-compiled in-memory module written to %TEMP%.

The second stage is a PowerShell-orchestrated C# loader. Banana RAT writes a C# source string to memory, invokes csc.exe via System.CodeDom.Compiler.CodeDomProvider to compile it into a transient .dll, then reflectively loads it via [System.Reflection.Assembly]::Load. The compiled assembly hosts the actual RAT functionality, intentionally splitting the kill chain across PowerShell -> csc.exe -> .NET reflection to defeat static AMSI/AV signatures on the .NET implant itself. The loader also drops persistence: an HKCU\Software\Microsoft\Windows\CurrentVersion\Run value pointing back to the .bat staging file, and a scheduled task named 'MicrosoftEdgeUpdateTaskMachineUA' for redundancy.

Once running, the implant beacons over HTTPS (443/tcp) and HTTP (80/tcp) to the C&C, registering itself with a victim ID derived from MAC + username + hostname. The C&C protocol is JSON over POST with AES-256-CBC body encryption, the same key family as the dropper. Commands supported include: screen_stream (MJPEG-style frame push for live RDP-style viewing), keylog_dump, overlay_open (loads one of 16 HTML banking overlays from the embedded resource pool), pix_intercept (monitors clipboard and any open windows for PIX QR codes, decodes them with ZXing.Net, swaps the destination key with an operator-controlled key, and re-encodes), browser_cookie_steal, and reverse_proxy.

The PIX interception module is the most operationally novel component. PIX is Brazil's instant-payment system, and QR codes are the dominant point-of-sale and peer-to-peer flow. Banana RAT continuously scans clipboard contents and visible window bitmaps (via PrintWindow GDI calls) for content matching the PIX BR Code payload format (starts with '00020126'). When a match is found, the ZXing.Net decoder extracts the merchant PIX key, the operator substitutes their own attacker-controlled PIX key, the EMV-style CRC16 is recomputed, and the modified QR is re-rendered and replaced in the clipboard or pasted back into the bank window. The victim then completes the payment to the attacker's account believing they are paying the legitimate merchant.

The overlay subsystem targets sixteen Brazilian institutions including Itau Unibanco, Bradesco, Santander Brasil, Caixa Economica Federal, Banco do Brasil, BTG Pactual, Nubank, Inter, C6 Bank, Sicoob, Sicredi, Banrisul, Original, Safra, Pan, and Mercado Pago. Each overlay is a HTML/JS page rendered in a borderless WebView2 window pinned over the legitimate banking application's login screen, harvesting credentials, transaction passwords, and 2FA OTPs in real time, then relaying them to the C&C for live-fraud operation.

Trend Micro coordinated disclosure with FEBRABAN (Brazilian Federation of Banks) given the regulator-level impact. At the time of publication, the primary C&C node 24.199.90.58 (a DigitalOcean droplet) remained publicly accessible with the build server exposed, and 162.141.111.227 was operating as a secondary fallback. The Trend Micro detections Backdoor.PS1.BANANARAT.A and Trojan.PS1.BANANARAT.A are deployed across their global telemetry.

Attribution to a Brazilian operator is moderate-confidence: Portuguese-language source comments, Brazilian timezone (BRT) build timestamps, exclusive targeting of Brazilian banks, PIX-specific functionality, and code-pattern overlap with Mekotio and Grandoreiro overlays. The 'Projeto Banana' codename appears in operator logs on the exposed server.

## MITRE ATT&CK

- T1566 Phishing
- T1566.001 Phishing: Spearphishing Attachment
- T1566.003 Phishing: Spearphishing via Service
- T1059.001 Command and Scripting Interpreter: PowerShell
- T1059.003 Command and Scripting Interpreter: Windows Command Shell
- T1204.002 User Execution: Malicious File
- T1106 Native API
- T1547.001 Registry Run Keys / Startup Folder
- T1053.005 Scheduled Task/Job: Scheduled Task
- T1027 Obfuscated Files or Information
- T1027.013 Obfuscated Files or Information: Encrypted/Encoded File
- T1620 Reflective Code Loading
- T1127 Trusted Developer Utilities Proxy Execution
- T1036.005 Match Legitimate Resource Name or Location
- T1685 Disable or Modify Tools
- T1056.001 Input Capture: Keylogging
- T1056.002 Input Capture: GUI Input Capture
- T1555.003 Credentials from Password Stores: Credentials from Web Browsers
- T1082 System Information Discovery
- T1057 Process Discovery
- T1113 Screen Capture
- T1115 Clipboard Data
- T1056 Input Capture
- T1071.001 Application Layer Protocol: Web Protocols
- T1573.001 Encrypted Channel: Symmetric Cryptography
- T1105 Ingress Tool Transfer
- T1090 Proxy
- T1041 Exfiltration Over C2 Channel
- T1657 Financial Theft
- T1565.002 Transmitted Data Manipulation

## Sources

- [Inside SHADOW-WATER-063 Banana RAT: From Build Server to Banking Fraud](https://www.trendmicro.com/en_us/research/26/e/banana-rat.html)
- [Tetrade Family Background — Kaspersky on Brazilian Banking Trojans (Grandoreiro/Mekotio/Casbaneiro/Guildma)](https://securelist.com/the-tetrade-brazilian-banking-malware/97779/)
- [Banco Central do Brasil — PIX Manual de Iniciacao do Recebedor (BR Code spec)](https://www.bcb.gov.br/estabilidadefinanceira/pix)
- [FEBRABAN Coordinated Disclosure Bulletin — Banana RAT](https://portal.febraban.org.br/)
- [MITRE ATT&CK T1059.001 PowerShell](https://attack.mitre.org/techniques/T1059/001/)
- [MITRE ATT&CK T1127.001 InstallUtil/csc.exe Trusted Developer Utility](https://attack.mitre.org/techniques/T1127/)
- [ZXing.Net QR Decoding Library](https://github.com/micjahn/ZXing.Net)
- [CHAVECLOAK Brazilian Banker Analysis](https://www.fortinet.com/blog/threat-research/chavecloak-banking-trojan-targets-brazil)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0534
