In this blog entry, researchers from the TrendAIβ’ MDR team discuss how they mapped the full end-to-end operation of SHADOW-WATER-063βs Banana RAT banking malware by analyzing server-side artifacts and victim-side data.
Targeting multiple industries worldwide, the InstallFix campaign uses fake Claude AI installer pages to trick users into running malware that collects system information, disables security features, achieves persistence, and connects to attacker-controlled C&C servers for additional payloads.
The Trend Microβ’ Managed Detection and Response team uncovered a threat campaign orchestrated by an active group, Water Curse. The threat actor exploits GitHub, one of the most trusted platforms for open-source software, as a delivery channel for weaponized repositories.