Banana RAT is a Windows-based Brazilian banking malware family characterized as a banking-oriented remote access trojan used to facilitate financial fraud, especially against Brazilian banking activity and Pix payment workflows. It has been associated with the threat cluster SHADOW-WATER-063 and has been observed targeting Brazilian financial institutions and related financial activity.
The malware is commonly delivered through invoice-themed social engineering, particularly fake NF-e electronic invoice lures, including malicious batch-script launchers distributed via phishing links and messaging platforms. Observed infection chains use hidden PowerShell staging, layered obfuscation, and encrypted payload retrieval. Operational infrastructure has shown evidence of active payload generation and obfuscation services, enabling polymorphic or rapidly changing variants rather than static samples.
Banana RAT establishes persistence through scheduled tasks and, in newer variants, VBScript-assisted launchers with hidden scheduled tasks; fallback user-level autorun persistence has also been observed. Recent branches introduced randomized installation folders and filenames to hinder signature-based detection. Newer variants also adopted encrypted WebSocket-based command and control using host-derived identifiers, while older branches used more static infrastructure patterns. Shared fallback infrastructure across branches indicates continuity of the same operation despite these implementation changes.
Functionally, Banana RAT supports remote fraud and surveillance operations. Reported capabilities include theft of banking credentials, monitoring of banking sessions, keylogging, screen and session monitoring, screen capture, remote input control, file transfer, and system and process discovery. It has also been linked to interference with payment transactions, including Pix-related fraud and QR-code manipulation or replacement during live transactions. These behaviors make it suitable both for credential theft and for hands-on fraudulent transaction execution.
Banana RAT has evolved toward stronger defense evasion through randomized file structures, encrypted communications, in-memory decryption, and obfuscated staging. The family is best understood as a full-featured banking-focused RAT rather than a simple downloader, with ongoing development aimed at improving persistence, operational resilience, and fraud enablement on compromised Windows endpoints.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A newly discovered banking trojan is targeting Brazilians by disguising itself as a legitimate electronic invoice. The malware, known as Banana RAT, uses fake NF-e (Nota Fiscal Eletronica) documents to trick victims into running malicious batch files that quietly install a powerful remote access tool on their Windows systems.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
Persistence relied on a scheduled task tied to a named executable... the newer version... shifts to a VBS launcher paired with a hidden scheduled task running with system-level privileges.
ANY.RUN behavior showed: hidden PowerShell execution, base64-encoded PowerShell, task-scheduler-backed execution
ofuscador.py, which took plain PowerShell commands and rewrote them into a scrambled character sequence reassembled and run at execution time.
variant updates to Banana RAT introduced randomized file structures and encrypted WebSocket communications
The earlier version... relied on fixed file names and folder paths designed to look like legitimate Windows update components. It used a lookalike domain with a spelling error...
Capability Assessment Based on payload content, sandbox behavior, and prior branch context, this branch supports: ... System and process discovery
The malware connects back to its command-and-control server on port 443 using a custom binary protocol encrypted with AES-256-CBC.
Communication with attacker servers happens over an encrypted WebSocket channel, using an address built from a hashed identifier unique to each infected computer...
36 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote access trojan whose updated variants use randomized file structures and encrypted WebSocket communications to support resilient command infrastructure and persistence.
Mentioned only in related content.
A Brazilian banking trojan/RAT mentioned only in related content.
Mentioned only as related content for a separate security guide.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.