Also known as: tracked as, services, other system resources, public key cryptography, one private, the file association, header, metamorphic, handler, Netshell, magic bytes, the IconEnvironmentDataBlock, mutating code
Shadow‑Water‑063 operates as part of a broader threat cluster known for building and deploying the Banana RAT banking trojan. Their FastAPI-based build system generates hash‑unique, highly polymorphic payloads that use layered obfuscation, AES‑wrapped binaries, and fileless PowerShell execution to bypass traditional defenses. Once in a victim network, the RAT provides remote input control, keylogging, screen streaming, bank‑branded overlays, and QR‑code interception, enabling operators to conduct fraud and redirect financial flows. The actor’s operations extend beyond the scope of simple credential theft; they strategically harvest tokens from corporate email services (Exchange, Office 365, Google Workspace) and use created cloud‑storage accounts (Dropbox, Mega, OneDrive, AWS S3) for staged exfiltration. In addition to banking theft, Shadow‑Water‑063 launches denial‑of‑service attacks on web, DNS, and application endpoints as both a diversion and potential extortion vector. Persistence is achieved through malicious code injection into cloud AMIs and Docker images, as well as hijacking of Windows service binaries via misconfigured file permissions. Their use of spoofed HTTP User-Agent headers and multi‑factor authentication bypasses further illustrates the sophistication of their adversary emulation techniques.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Shadow‑Water‑063 is a financially-driven actor group operating primarily in Brazil, deploying the Banana RAT banking trojan to execute fraudulent invoice payments and credential theft across 16 major banks. Their toolkit blends polymorphic malware, public‑cloud exfiltration, email‑account abuse, and denial‑of‑service attacks to evade detection and disrupt services. The group demonstrates sophisticated persistence via cloud images and service hijacking, while actively targeting MFA mechanisms.
Goals & Targeting
Shadow‑Water‑063’s strategic objectives are clear: maximize financial gain by exploiting Brazil’s banking infrastructure while maintaining operational stealth. By targeting a curated list of 16 banks, the actor leverages automated credential harvesting to broaden reach and reduce manual effort. The persistence mechanisms focused on cloud images and service binaries indicate an intent for long‑term footholds, enabling repeated fraud cycles and revenue generation. The group also demonstrates a willingness to employ denial‑of‑service tactics and MFA bypass techniques to mitigate detection risk and maintain continuity of operations, underscoring a highly methodical approach that balances impact with survivability.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Shadow‑Water‑063’s operations reveal a focused but high‑profile campaign against Brazilian financial institutions, beginning with the deployment of Banana RAT and rapid expansion into credential harvesting via new email and cloud‑storage accounts. The actor stages data exfiltration through public services such as Dropbox and OneDrive while simultaneously launching Denial‑of‑Service attacks to distract or extort victims during lateral movement phases. Polymorphic payloads, service binary hijacking, and persistence in cloud images enable the threat actor to maintain long‑term footholds and repeat fraudulent transactions. Historically, these operations have targeted 16 major banks and crypto exchanges, demonstrating efficient automation with tools like MailSniper for credential discovery. The group's operational tempo is aggressive yet carefully staged to avoid detection. While primarily confined to Brazil, there are indications that Shadow‑Water‑063 may diversify its infrastructure or victim scope in the future, though concrete evidence remains limited.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The available evidence demonstrates a clear link between Shadow‑Water‑063 and the Banana RAT trojan, including documented tactics such as credential harvesting, cloud exfiltration, denial‑of‑service attacks, and polymorphic malware. However, attribution is largely based on signature similarity and operational patterns; definitive proof of operator control remains limited. Visibility into the broader C2 infrastructure and potential victims outside Brazil is incomplete, leading to moderate confidence in the actor’s full capabilities and geographic scope.
No campaigns linked yet.
No observed data linked yet.
47
Techniques
44
Tools
0
Campaigns
43
IOCs
0
Observed Data
14
Tactics