{"podcast":{"title":"Research Saturday","slug":"research-saturday-1377435","podcast_index_feed_id":1377435,"rss_url":"https://feeds.megaphone.fm/cyberwire-research-saturday","website_url":"https://thecyberwire.com/podcasts/research-saturday","image_url":"https://megaphone.imgix.net/podcasts/720fb496-dcfb-11ea-a475-bbdae30535a9/image/8f3cd4038c81bba2a8ea4ca89f3e23c4.png?ixlib=rails-4.3.1&max-w=3000&max-h=3000&fit=crop&auto=format,compress","author":"N2K Networks Inc.","episode_count":458,"summary":"Every Saturday, we sit down with cybersecurity researchers to talk shop about the latest threats, vulnerabilities, and technical discoveries.","last_synced_at":"2026-07-26T04:20:01.844149+00:00","page_url":"https://stenobird.com/podcast/research-saturday-1377435"},"episode":{"title":"Peeling back Banana RAT.","slug":"peeling-back-banana-rat","published_at":"2026-06-20T05:00:00+00:00","page_url":"https://stenobird.com/podcast/research-saturday-1377435/peeling-back-banana-rat","show_page_url":"https://stenobird.com/podcast/research-saturday-1377435","url":"https://thecyberwire.com/podcasts/research-saturday/430/notes","audio_url":"https://pdst.fm/e/pdrl.fm/6ec23a/traffic.megaphone.fm/CYBW4149465288.mp3?updated=1743778763","summary":"This week, we are joined by Tom Kellermann, TrendAI's VP of AI Security and Threat Research, discussing their work on \"Inside SHADOW-WATER-063’s Banana RAT: From Build Server to Banking Fraud.\" Researchers from TrendAI's MDR team uncovered the full operation behind Banana RAT, a sophisticated banking trojan they track as SHADOW-WATER-063, by analyzing both attacker infrastructure and infected victim systems. The malware uses fileless PowerShell execution, layered obfuscation, and remote-control capabilities to steal credentials, manipulate banking sessions, intercept Pix QR code payments, and facilitate financial fraud targeting Brazilian banks. The campaign appears to be operated by a Brazilian Portuguese-speaking cybercriminal group with ties to the broader Tetrade banking malware ecosystem and may be evolving toward a malware-as-a-service model. The research and executive brief can be found here: ⁠Inside SHADOW-WATER-063’s Banana RAT: From Build Server to Banking Fraud","meta_description":"This week, we are joined by Tom Kellermann, TrendAI's VP of AI Security and Threat Research, discussing their work on \"Inside SHADOW-WATER-063’s Banana RA…","key_points":[],"chapters":[],"topics":[],"duration_seconds":1739,"processing_state":"not_requested","actions":[{"name":"request_transcript","method":"POST","url":"https://stenobird.com/v1/public/podcasts/research-saturday-1377435/episodes/peeling-back-banana-rat/transcription-requests","description":"Idempotently request low-priority transcript generation for this episode."},{"name":"read_markdown","method":"GET","url":"https://stenobird.com/podcast/research-saturday-1377435/peeling-back-banana-rat.md","description":"Read the agent-friendly Markdown representation of this episode resource."}]}}