A sophisticated new Brazilian banking trojan that uses advanced evasion techniques and self-propagating worm modules to target financial platforms.
Tracked under the REF3076 campaign, this malware represents a major evolution of the older MAVERICK and SORVEPOTEL families, leveraging trusted communication channels such as WhatsApp and Microsoft Outlook to distribute its payload rapidly.
TCLBANKER Spreads Through WhatsApp
The infection sequence begins by abusing a legitimately signed Logitech application, the Logi AI Prompt Builder, to execute a malicious payload via DLL sideloading.
Once active, the TCLBANKER loader heavily relies on environment-gated payload decryption to evade detection.
By evaluating system disk information, running processes, debugging tools, and verifying that the system language is set to Brazilian Portuguese, the malware generates a unique environment hash.

If the malware detects a security sandbox or analysis tool, the generated hash will be incorrect, causing the payload to fail to decrypt and halt execution entirely silently.
Furthermore, a dedicated watchdog subsystem continuously scans for analysis frameworks, ensuring the malware remains hidden from researchers while establishing persistence through hidden scheduled tasks.

Once the primary banking trojan is deployed, it actively monitors the victim’s foreground web browser using user interface automation.
The URL monitor specifically targets major browsers, including Google Chrome, Mozilla Firefox,
Microsoft Edge, Brave, Opera, and Vivaldi the malware searches for connections to 59 different Brazilian banking, cryptocurrency, and financial technology domains.
When a victim navigates to one of these targeted sites, the malware initializes a secure WebSocket command-and-control session.

The most dangerous feature of this stage is its custom full-screen overlay framework, designed to execute operator-driven social engineering attacks.
According to Elastic research, the rapid spread of TCLBANKER is driven by its secondary worm module which operates through two distinct spam agents that abuse trusted communication channels.
The first agent functions as a WhatsApp bot that specifically targets Chromium-based browsers on the infected machine.
It searches for authenticated WhatsApp Web sessions and clones the necessary browser profiles. It uses a hidden browser instance to hijack the account silently. To ensure success, it injects JavaScript to bypass bot-detection frameworks.
| Opcode | Capability Summary | Technical Description |
|---|---|---|
| 2 | Initialization | Registration ACK, starts the Task Manager killer to prevent victim interference. |
| 4 | Disconnect | Graceful WebSocket disconnect. |
| 5 | Suicide (Kill All) | Kills all sibling processes and exits. |
| 6 | Reboot System | Forced reboot (shutdown.exe /r /t 0 /f). |
It waits to verify that the chat interface loads correctly without prompting for a QR code scan.
The malware then harvests the victim’s contacts and dispatches localized phishing messages containing the trojanized installer.
By sending malicious links directly from the victim’s account to their personal contacts, attackers bypass traditional security gateways and leverage the existing trust between individuals.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.