In this blog entry, researchers from the TrendAIβ’ MDR team discuss how they mapped the full end-to-end operation of SHADOW-WATER-063βs Banana RAT banking malware by analyzing server-side artifacts and victim-side data.
Targeting multiple industries worldwide, the InstallFix campaign uses fake Claude AI installer pages to trick users into running malware that collects system information, disables security features, achieves persistence, and connects to attacker-controlled C&C servers for additional payloads.