Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors shadow-water-063

Also known as: tracked as, services, other system resources, public key cryptography, one private, the file association, header, metamorphic, handler, Netshell, magic bytes, the IconEnvironmentDataBlock, mutating code

Description

Shadow‑Water‑063 operates as part of a broader threat cluster known for building and deploying the Banana RAT banking trojan. Their FastAPI-based build system generates hash‑unique, highly polymorphic payloads that use layered obfuscation, AES‑wrapped binaries, and fileless PowerShell execution to bypass traditional defenses. Once in a victim network, the RAT provides remote input control, keylogging, screen streaming, bank‑branded overlays, and QR‑code interception, enabling operators to conduct fraud and redirect financial flows. The actor’s operations extend beyond the scope of simple credential theft; they strategically harvest tokens from corporate email services (Exchange, Office 365, Google Workspace) and use created cloud‑storage accounts (Dropbox, Mega, OneDrive, AWS S3) for staged exfiltration. In addition to banking theft, Shadow‑Water‑063 launches denial‑of‑service attacks on web, DNS, and application endpoints as both a diversion and potential extortion vector. Persistence is achieved through malicious code injection into cloud AMIs and Docker images, as well as hijacking of Windows service binaries via misconfigured file permissions. Their use of spoofed HTTP User-Agent headers and multi‑factor authentication bypasses further illustrates the sophistication of their adversary emulation techniques.

Goals & Targeting

Targeted Sectors

Financial services
Defense
Media
Critical infrastructure
Information technology

Targeted Countries / Regions

Brazil
BR

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 2 hours ago

Executive Summary

Shadow‑Water‑063 is a financially-driven actor group operating primarily in Brazil, deploying the Banana RAT banking trojan to execute fraudulent invoice payments and credential theft across 16 major banks. Their toolkit blends polymorphic malware, public‑cloud exfiltration, email‑account abuse, and denial‑of‑service attacks to evade detection and disrupt services. The group demonstrates sophisticated persistence via cloud images and service hijacking, while actively targeting MFA mechanisms.

Goals & Targeting

Shadow‑Water‑063’s strategic objectives are clear: maximize financial gain by exploiting Brazil’s banking infrastructure while maintaining operational stealth. By targeting a curated list of 16 banks, the actor leverages automated credential harvesting to broaden reach and reduce manual effort. The persistence mechanisms focused on cloud images and service binaries indicate an intent for long‑term footholds, enabling repeated fraud cycles and revenue generation. The group also demonstrates a willingness to employ denial‑of‑service tactics and MFA bypass techniques to mitigate detection risk and maintain continuity of operations, underscoring a highly methodical approach that balances impact with survivability.

Enhanced Description

Key Capabilities

  • Banking fraud via fake invoices targeting Brazilian banks
  • Credential harvesting from email services (Exchange, Office 365, Google Workspace)
  • Creation of operational email and cloud storage accounts
  • Exfiltration over public cloud storage providers (Dropbox, MEGA, OneDrive, AWS S3)
  • Denial-of-service attacks on web, DNS, and application endpoints
  • Remote service exploitation for lateral movement within victim networks
  • Automated credential searches using tools like MailSniper
  • Service binary hijacking through misconfigured file permissions
  • Persistence via malicious code in cloud or container images
  • Spoofed HTTP User-Agent headers to blend with legitimate traffic
  • Targeting and bypassing multi-factor authentication mechanisms
  • Polymorphic or mutating malware for signature evasion

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
Impact
Exfiltration

ATT&CK Techniques

T1010
T1037
T1059
T1071
T1078
T1087
T1092
T1098
T1110
T1115
T1119
T1123
T1185
T1190
T1197
T1498
T1499
T1526
T1531
T1537
T1543
T1554
T1555
T1557
T1580
T1583
T1584
T1586
T1595
T1609
T1612
T1613
T1619
T1650
T1651
T1659
T1671
T1020
T1021
T1027

Software / Tooling

Banana RAT
MailSniper

Campaigns & Victims

Shadow‑Water‑063’s operations reveal a focused but high‑profile campaign against Brazilian financial institutions, beginning with the deployment of Banana RAT and rapid expansion into credential harvesting via new email and cloud‑storage accounts. The actor stages data exfiltration through public services such as Dropbox and OneDrive while simultaneously launching Denial‑of‑Service attacks to distract or extort victims during lateral movement phases. Polymorphic payloads, service binary hijacking, and persistence in cloud images enable the threat actor to maintain long‑term footholds and repeat fraudulent transactions. Historically, these operations have targeted 16 major banks and crypto exchanges, demonstrating efficient automation with tools like MailSniper for credential discovery. The group's operational tempo is aggressive yet carefully staged to avoid detection. While primarily confined to Brazil, there are indications that Shadow‑Water‑063 may diversify its infrastructure or victim scope in the future, though concrete evidence remains limited.

IOC Patterns

  • Public Cloud Storage Exfiltration
  • Email Account Creation Abuse
  • Credential Harvesting via MailSniper
  • Service Binary Hijacking through Permission Misconfiguration
  • Malicious Cloud Image Persistence
  • HTTP User-Agent Spoofing
  • Network DoS Traffic
  • Polymorphic Malware Signatures

Recommended Actions

  • Enforce multi‑factor authentication across all employee accounts.
  • Monitor and restrict the creation of new email and cloud storage accounts, flagging suspicious activity.
  • Patch public‑facing applications promptly and harden firewall rules to detect/block DoS traffic.
  • Deploy intrusion detection/prevention systems tuned to detect credential‑harvesting tools such as MailSniper.
  • Inspect outbound traffic for exfiltration over public cloud storage services (Dropbox, MEGA, OneDrive, AWS S3).
  • Conduct regular phishing awareness training and simulated attacks.
  • Harden Windows service binary permissions to prevent hijacking of service executables.

Suggested Tags

shadow-water-063
banana-rat
banking-trojan
financial-malware
phishing
cloud-exfiltration
denial-of-service
mail-sniper
email-account-abuse
service-binary-hijacking
cloud-image-persistence
user-agent-spoofing
mfa-by-pass
polymorphic-malware

Confidence Assessment

The available evidence demonstrates a clear link between Shadow‑Water‑063 and the Banana RAT trojan, including documented tactics such as credential harvesting, cloud exfiltration, denial‑of‑service attacks, and polymorphic malware. However, attribution is largely based on signature similarity and operational patterns; definitive proof of operator control remains limited. Visibility into the broader C2 infrastructure and potential victims outside Brazil is incomplete, leading to moderate confidence in the actor’s full capabilities and geographic scope.

ATT&CK Techniques

Lateral Movement
1 technique
Privilege Escalation
1 technique
Reconnaissance
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. attack.mitre.org — Cited by web research for: services
  2. www.trendmicro.com — Cited by web research for: Payload
  3. malpedia.caad.fkie.fraunhofer.de — Cited by web research for: curl
  4. www.trendmicro.com — Cited by web research for: Critical Infrastructure
  5. https://malpedia.caad.fkie.fraunhofer.de/actors — Cited by AI analysis.
  6. https://exchange.xforce.ibmcloud.com/osint/guid:4076fb9af49543fc8060f131db2c0764 — Cited by AI analysis.
  7. https://hackread.com/banana-rat-malware-fake-invoices-16-brazilian-banks/ — Cited by AI analysis.
  8. https://socprime.com/active-threats/inside-shadow-water-063s-banana-rat-from-build-server-to-banking-fraud/ — Cited by AI analysis.
  9. https://attack.mitre.org/tactics/ — Cited by AI analysis.

Intel Summary

47

Techniques

44

Tools

0

Campaigns

43

IOCs

0

Observed Data

14

Tactics

Tags

Financial Targeting
APT
Banking Trojan
Financial Threat
Brazil
Portuguese
shadow-water-063
banana-rat
banking-trojan
financial-malware
phishing
cloud-exfiltration
denial-of-service
mail-sniper
email-account-abuse
service-binary-hijacking
cloud-image-persistence
user-agent-spoofing
mfa-by-pass
polymorphic-malware

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
B
Confidence
55%
Added
May 21, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.