← Back to Feed

Inside SHADOW-WATER-063’s Banana RAT: From Build Server to Banking Fraud

May 19, 2026 · Trend Micro · Severity: HIGH

In this blog entry, researchers from the TrendAI™ MDR team discuss how they mapped the full end-to-end operation of SHADOW-WATER-063’s Banana RAT banking malware by analyzing server-side artifacts and victim-side data.

Key Takeaways

  • TrendAI MDR researchers mapped the full end-to-end operation of SHADOW-WATER-063's Banana RAT banking malware by analyzing server-side artifacts and victim-side data.
  • The analysis traces the campaign from build server to banking fraud, revealing how the group orchestrates credential theft and fraudulent transactions.
  • Financial institutions should hunt for Banana RAT indicators derived from the build server analysis and strengthen banking fraud monitoring.
☕ Buy a Coffee