Episode

Peeling back Banana RAT. [Research Saturday]

Podcast
CyberWire Daily
Published
Jun 20, 2026
Duration seconds
1739
Processing state
not_requested
Canonical source
https://thecyberwire.com/podcasts/research-saturday/430/notes
Audio
https://pdst.fm/e/pdrl.fm/85df76/traffic.megaphone.fm/CYBW6020151245.mp3?updated=1743778763
JSON
/v1/public/podcasts/cyberwire-daily-454880/episodes/peeling-back-banana-rat-research-saturday
Markdown
/podcast/cyberwire-daily-454880/peeling-back-banana-rat-research-saturday.md

Actions

  • POST https://stenobird.com/v1/public/podcasts/cyberwire-daily-454880/episodes/peeling-back-banana-rat-research-saturday/transcription-requests
    Idempotently request low-priority transcript generation for this episode.
  • GET https://stenobird.com/podcast/cyberwire-daily-454880/peeling-back-banana-rat-research-saturday.md
    Read the agent-friendly Markdown representation of this episode resource.

Summary

This week, we are joined by Tom Kellermann, Trend Micro's VP of AI Security and Threat Research, discussing their work on "Inside SHADOW-WATER-063’s Banana RAT: From Build Server to Banking Fraud." Researchers from Trend Micro's MDR team uncovered the full operation behind Banana RAT, a sophisticated banking trojan they track as SHADOW-WATER-063, by analyzing both attacker infrastructure and infected victim systems. The malware uses fileless PowerShell execution, layered obfuscation, and remote-control capabilities to steal credentials, manipulate banking sessions, intercept Pix QR code payments, and facilitate financial fraud targeting Brazilian banks. The campaign appears to be operated by a Brazilian Portuguese-speaking cybercriminal group with ties to the broader Tetrade banking malware ecosystem and may be evolving toward a malware-as-a-service model. The research and executive brief can be found here: ⁠Inside SHADOW-WATER-063’s Banana RAT: From Build Server to Banking Fraud Learn more about your ad choices. Visit megaphone.fm/adchoices