{"podcast":{"title":"CyberWire Daily","slug":"cyberwire-daily-454880","podcast_index_feed_id":454880,"rss_url":"https://feeds.megaphone.fm/cyberwire-daily-podcast","website_url":"https://thecyberwire.com/podcasts/daily-podcast","image_url":"https://megaphone.imgix.net/podcasts/58ab7ae0-def8-11ea-b34c-b35b208b0539/image/8676ed612d7a335a98a9173d70cb11be.png?ixlib=rails-4.3.1&max-w=3000&max-h=3000&fit=crop&auto=format,compress","author":"N2K Networks, Inc.","episode_count":3697,"summary":"The daily cybersecurity news and analysis industry leaders depend on. Published each weekday, the program also includes interviews with a wide spectrum of experts from industry, academia, and research organizations all over the world.","last_synced_at":"2026-07-19T06:20:36.947551+00:00","page_url":"https://stenobird.com/podcast/cyberwire-daily-454880"},"episode":{"title":"Peeling back Banana RAT. [Research Saturday]","slug":"peeling-back-banana-rat-research-saturday","published_at":"2026-06-20T07:00:00+00:00","page_url":"https://stenobird.com/podcast/cyberwire-daily-454880/peeling-back-banana-rat-research-saturday","show_page_url":"https://stenobird.com/podcast/cyberwire-daily-454880","url":"https://thecyberwire.com/podcasts/research-saturday/430/notes","audio_url":"https://pdst.fm/e/pdrl.fm/85df76/traffic.megaphone.fm/CYBW6020151245.mp3?updated=1743778763","summary":"This week, we are joined by Tom Kellermann, Trend Micro's VP of AI Security and Threat Research, discussing their work on \"Inside SHADOW-WATER-063’s Banana RAT: From Build Server to Banking Fraud.\" Researchers from Trend Micro's MDR team uncovered the full operation behind Banana RAT, a sophisticated banking trojan they track as SHADOW-WATER-063, by analyzing both attacker infrastructure and infected victim systems. The malware uses fileless PowerShell execution, layered obfuscation, and remote-control capabilities to steal credentials, manipulate banking sessions, intercept Pix QR code payments, and facilitate financial fraud targeting Brazilian banks. The campaign appears to be operated by a Brazilian Portuguese-speaking cybercriminal group with ties to the broader Tetrade banking malware ecosystem and may be evolving toward a malware-as-a-service model. The research and executive brief can be found here: ⁠Inside SHADOW-WATER-063’s Banana RAT: From Build Server to Banking Fraud Learn more about your ad choices. Visit megaphone.fm/adchoices","meta_description":"This week, we are joined by Tom Kellermann, Trend Micro's VP of AI Security and Threat Research, discussing their work on \"Inside SHADOW-WATER-063’s Banan…","key_points":[],"chapters":[],"topics":[],"duration_seconds":1739,"processing_state":"not_requested","actions":[{"name":"request_transcript","method":"POST","url":"https://stenobird.com/v1/public/podcasts/cyberwire-daily-454880/episodes/peeling-back-banana-rat-research-saturday/transcription-requests","description":"Idempotently request low-priority transcript generation for this episode."},{"name":"read_markdown","method":"GET","url":"https://stenobird.com/podcast/cyberwire-daily-454880/peeling-back-banana-rat-research-saturday.md","description":"Read the agent-friendly Markdown representation of this episode resource."}]}}