SmartRAT is a Brazil-focused banking remote access trojan written entirely in PowerShell and used to target Windows users, particularly customers of Brazilian banks and payment services. It has been observed in phishing and ClickFix campaigns that impersonate Brazilian financial institutions and use layered social engineering, including fake verification pages and fake system error screens, to trick victims into executing malicious PowerShell commands.
Once installed, SmartRAT provides full remote access and is designed for financial theft. Its capabilities include encrypted command-and-control communications, arbitrary PowerShell execution, screen capture, keyboard and mouse control, clipboard manipulation, file browsing and exfiltration, process and service listing, and foreground window monitoring. It is especially tailored for banking fraud: it can log keystrokes, display fake bank-branded credential forms, monitor for targeted banking and payment windows, and alert operators when victims interact with financial services. It also supports QR-code interception and replacement to facilitate fraudulent transactions.
SmartRAT uses multiple persistence mechanisms, including scheduled tasks, Windows startup entries, and, when elevated access is obtained, installation as a Windows service running with SYSTEM privileges. It can prompt for UAC approval and includes logic to continue operating even when elevation is denied. The malware also compiles embedded C# components in memory to support functions such as input handling, overlay rendering, screen capture, keylogging, and QR detection.
The malware has been associated with campaigns using AI-assisted phishing infrastructure and typosquatting sites aimed at Brazilian banking customers. Its operators appear focused on credential theft, banking-session abuse, and post-compromise remote control in support of financial fraud.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
SmartRAT hides itself by disguising its files and scheduled tasks under Microsoft Edge update names, blending in with legitimate Windows processes.
This threat features encrypted C2 communications, remote system control, credential theft via keylogging and banking overlays, and persistence through Windows services and scheduled tasks.
Execution T1059 Command and Scripting Interpreter Use built-in interpreters (like PowerShell) to run malicious commands/scripts.
This post analyzes a specific ClickFix campaign that mimics a Brazilian bank to deploy a newly discovered, PowerShell-based malware dubbed SmartRAT.
SmartRAT hides itself by disguising its files and scheduled tasks under Microsoft Edge update names, blending in with legitimate Windows processes.
This threat features encrypted C2 communications, remote system control, credential theft via keylogging and banking overlays, and persistence through Windows services and scheduled tasks.
SmartRAT hides itself by disguising its files and scheduled tasks under Microsoft Edge update names, blending in with legitimate Windows processes.
This threat features encrypted C2 communications, remote system control, credential theft via keylogging and banking overlays, and persistence through Windows services and scheduled tasks.
SmartRAT also compiles another C# component that uses DuplicateTokenEx and CreateProcessAsUser to spawn a new PowerShell process using the current user’s session, even when the RAT is running as SYSTEM.
This threat features encrypted C2 communications, remote system control, credential theft via keylogging and banking overlays, and persistence through Windows services and scheduled tasks.
SmartRAT decrypts two C2 server configurations. The first is decrypted using XOR with the key 2... The fallback C2 is an IP address that is decrypted using XOR with the key 233.
SmartRAT hides itself by disguising its files and scheduled tasks under Microsoft Edge update names, blending in with legitimate Windows processes.
0xA2 SystemCommand... uninstall: Complete self-removal; delete the service, scheduled tasks, registry keys, and all files, then exit.
SmartRAT also compiles another C# component that uses DuplicateTokenEx and CreateProcessAsUser to spawn a new PowerShell process using the current user’s session, even when the RAT is running as SYSTEM.
The attacker can then take over the screen, inject keystrokes, block victim input, and steal whatever data is entered.
The attacker can then take over the screen, inject keystrokes, block victim input, and steal whatever data is entered.
This threat features encrypted C2 communications, remote system control, credential theft via keylogging and banking overlays...
This threat features encrypted C2 communications, remote system control, credential theft via keylogging and banking overlays...
One striking discovery is that the attackers also used AI tools to build their command-and-control panel, a web interface used to manage infected machines.
14 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only as a comparison in cleanup guidance for similar endpoint checks.
Referenced as a Windows banking trojan delivered through fake banking pages.
PowerShell-based remote access malware used against Brazilian banking customers. It records keystrokes, captures screenshots, intercepts QR codes, monitors browser windows for banking activity, displays fake bank forms to steal credentials, can inject keystrokes, block victim input, and persist via scheduled tasks, registry startup entries, or as a Windows service with SYSTEM-level access.
PowerShell-based remote access trojan with encrypted C2 communications, remote system control, credential theft via keylogging and banking overlays, and persistence through Windows services and scheduled tasks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.