Banana RAT Malware in Fake Invoices Hits Customers at 16 Brazilian Banks
A new threat called Banana RAT malware is targeting banking customers in Brazil, using fake documents and tools to compromise devices and steal funds. Cybersecurity experts from TrendAI (formerly Trend Micro) found the operation and shared its details with Hackread.com.
Inside the Attack Pipeline
The scam was still active when TrendAI experts began investigating. They collected data directly from the hackers’ live servers between 17 and 22 April 2026 to fully understand how the scam works.
They found that the attackers speak Brazilian Portuguese, operate under the temporary name SHADOW-WATER-063, and are targeting individuals in Brazil’s business sector to deliver the Banana RAT malware. The hackers’ own code stamps revealed their internal project codename as Projeto Banana.
Further probing revealed that scammers trick victims via WhatsApp or phishing links into downloading a fake electronic invoice file named Consultar_NF-e.bat from the domain convitemundial2026.com. When they click on it, this batch...
Copyright of this story solely belongs to hackread.com. To see the full text click HERE