securityonline.info 5/25/2026, 7:31:12 AM · external

Banana RAT hits Brazilian banks via fileless, live session hijack

Banana RAT hits Brazilian banks via fileless, live session hijack
CyberSIXT Evidence Panel
Primary Source trendmicro.com
Threat Actor
SHADOW-WATER-063

THE article discusses the Banana RAT (Remote Access Trojan), attributed to a cybercriminal group known as SHADOW-WATER-063, targeting Brazilian financial institutions. The trojan employs advanced strategies for financial theft, utilizing a fileless execution model that operates primarily in memory to evade detection.

Key features include an operator-driven control system allowing live manipulation of banking sessions, deceptive overlays to mislead users, and specialized modules for intercepting cryptocurrency transactions. TrendAI emphasizes the need for financial institutions to adopt robust behavioral profiling and monitor for unusual PowerShell activity to combat this sophisticated threat.

View Primary Source Via securityonline.info

Article by CyberSIXT