CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Inside SHADOW-WATER-063’s Banana RAT: From Build Server to Banking Fraud

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6208

As cited

Copy frozen at (site build).

threat intel

Inside SHADOW-WATER-063’s Banana RAT: From Build Server to Banking Fraud

Researchers from the TrendAI MDR team analyzed server-side and victim-side artifacts to map the complete operational flow of Banana RAT, a remote access trojan (RAT) used by threat group SHADOW-WATER-063 for banking fraud. The analysis traced the malware from its build server through to its impact on victims.

Why it matters: Banking and financial services organizations need to understand this RAT's delivery and command infrastructure to detect and block Banana RAT infections before attackers gain remote access to critical systems.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary