Banking Trojan Banana RAT Exploits Brazil's NF-e System
Article Content
- •The Banana RAT trojan is disguised as legitimate NF-e documents to trick users.
- •The attack primarily targets Brazilian financial institutions, indicating a focused campaign.
- •Victims are deceived into executing malicious files that install remote access tools.
Hackers are leveraging Brazil's electronic invoice system (NF-e) to distribute the Banana RAT banking trojan, specifically targeting Brazilian financial institutions. This campaign, attributed to the financially motivated threat cluster SHADOW-WATER-063, uses fake NF-e documents to deceive victims into executing malicious batch files. Once activated, the trojan installs a remote access tool on Windows systems, allowing attackers to gain unauthorized access. The operation has raised alarms due to its sophistication and focus on financial theft. Analysts have gained insights into the attack methods, but the full scope of the campaign's impact remains under investigation. As of now, the campaign is ongoing, and users are advised to remain vigilant.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Banana RAT in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
BlueMoon Exploit Kit Targeting Chrome and Windows by Multiple State Actors A new exploit kit named BlueMoon has been rapidly adopted by at least four espionage groups, primarily linked to China, exploiting vulnerabilities in Google Chrome and Microsoft Windows. The first observed use of BlueMoon was on August 28, 2026, by the China-aligned threat actor TA412, with subsequent adoption by…