SHADOW-WATER-063 is a Brazil-linked cybercrime cluster associated with the Banana RAT banking trojan and assessed to operate against Brazil’s financial ecosystem. The activity is focused on remote fraud and surveillance against Brazilian financial institutions and localized cryptocurrency exchanges, with delivery commonly using fake NF-e electronic invoice lures distributed through phishing links and messaging platforms. The operation targets Windows systems and uses a staged infection chain centered on hidden PowerShell execution, in-memory payload decryption, scheduled-task persistence, and layered obfuscation to reduce detection. Banana RAT functions as a banking trojan and remote access platform. Reported capabilities include keylogging, live screen streaming, remote input control, and the display of fraudulent banking overlays designed to imitate legitimate security prompts. The malware also supports manipulation of Pix payment workflows, including interception or replacement of Pix QR codes during transactions, indicating a strong focus on financial theft within Brazil’s banking environment. The campaign has also been described as using polymorphic payload generation and resilient command-and-control design, suggesting an effort to produce unique payloads per victim and maintain operational continuity. Operational artifacts and server-side code have been linked to Brazilian Portuguese usage, and the cluster has been associated with an internal project codename, Projeto Banana. The activity has been assessed as highly targeted against major Brazilian banks and related financial services. There is also reporting that the operation may be run in a Malware-as-a-Service model, but that aspect is not firmly established. No additional widely used aliases beyond SHADOW-WATER-063 are currently available from the supplied facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
15 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
17 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a targeted Brazilian banking trojan campaign using Banana RAT disguised as NF-e electronic invoice files to compromise victims in Brazil’s financial sector and localized cryptocurrency exchanges.
Associated with the Banana RAT banking trojan targeting Brazilian financial institutions. The operation uses polymorphic payload generation, staged deployment, fileless PowerShell execution, layered obfuscation, and AES-wrapped payloads to evade detection, enabling remote input control, keylogging, screen streaming, and Pix QR code fraud.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.