ThreatCluster

Banking Trojan Banana RAT Exploits Brazil's NF-e System

First seen 22 May 2026, 21:11 UTC GbhackersCybersecuritynews 88% similarity 67

Article Content

Browse articles
ThreatCluster

Hackers are leveraging Brazil's electronic invoice system (NF-e) to distribute the Banana RAT banking trojan, specifically targeting Brazilian financial institutions. This campaign, attributed to the financially motivated threat cluster SHADOW-WATER-063, uses fake NF-e documents to deceive victims into executing malicious batch files. Once activated, the trojan installs a remote access tool on Windows systems, allowing attackers to gain unauthorized access. The operation has raised alarms due to its sophistication and focus on financial theft. Analysts have gained insights into the attack methods, but the full scope of the campaign's impact remains under investigation. As of now, the campaign is ongoing, and users are advised to remain vigilant.

Key Points: • The Banana RAT trojan is disguised as legitimate NF-e documents to trick users. • The attack primarily targets Brazilian financial institutions, indicating a focused campaign. • Victims are deceived into executing malicious files that install remote access tools.

ThreatCluster AI

Timeline

2026-05-22
Banana RAT campaign identified
Hackers are using Brazil's NF-e system to distribute the Banana RAT banking trojan targeting financial institutions.
Gbhackers
2026-05-22
Malware installation method detailed
The trojan tricks users into running malicious batch files disguised as NF-e documents, leading to remote access tool installation.
Cybersecuritynews

Community

Browse all →