Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Inside Banana RAT: From Build Server to Banking Fraud

162.141.111.227

TLP:CLEAR
Active

IPv4 Address

Description

An MDR investigation successfully mapped the complete operational infrastructure of Banana RAT, a Brazilian banking trojan operated by threat cluster SHADOW-WATER-063. The investigation uncovered both server-side and client-side components, revealing a sophisticated FastAPI-based polymorphic payload generation system that produces hash-unique builds to evade detection. The malware employs layered obfuscation, AES-wrapped payloads, and fileless PowerShell execution. Once deployed, it enables operator-driven fraud through remote input control, keylogging, screen streaming, bank-branded overlays, and Pix QR code interception specifically targeting Brazilian financial institutions. The tooling e... | Shodan InternetDB; ports: 135; hostnames: 162-141.111.227-sidbrasil.com.br

Sightings (0)

No sightings recorded yet

Details

Name / Label
Inside Banana RAT: From Build Server to Banking Fraud
Pattern Type
STIX
Confidence
75%
Valid From
May 21, 2026 03:05
Total Sightings
0
Added
May 21, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of 162.141.111.227

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.